CVE-2018-0745
MEDIUMWindows 10 1703-1709 and Windows Server 2016 - Information Disclosure via Memory Object Handling
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-0745. PoCs published by Google Security Research.
AI-analyzed exploit summary This exploit demonstrates an information leak vulnerability in Windows 10 version 1709 32-bit via the nt!NtQueryInformationProcess system call with information class 76. It sprays the kernel stack with controlled data and leaks uninitialized kernel stack memory to user-mode.
Description
The Windows kernel in Windows 10 version 1703. Windows 10 version 1709, and Windows Server, version 1709 allows an information disclosure vulnerability due to the way objects are handled in memory, aka "Windows Information Disclosure Vulnerability". This CVE ID is unique from CVE-2018-0746 and CVE-2018-0747.
Exploits (1)
This exploit demonstrates an information leak vulnerability in Windows 10 version 1709 32-bit via the nt!NtQueryInformationProcess system call with information class 76. It sprays the kernel stack with controlled data and leaks uninitialized kernel stack memory to user-mode.
References (4)
Scores
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N