102353vdb entry
http://www.securityfocus.com/bid/102353 CVE-2018-0745
MEDIUM
Microsoft Windows - 'nt!NtQueryInformationProcess (information class 76_ QueryProcessEnergyValues)' Kernel Stack Memory Disclosure
Record summary
CVE-2018-0745 has a selected CVSS score of 4.7 (medium); EIP currently links 1 catalogued exploit.
Description
The Windows kernel in Windows 10 version 1703. Windows 10 version 1709, and Windows Server, version 1709 allows an information disclosure vulnerability due to the way objects are handled in memory, aka "Windows Information Disclosure Vulnerability". This CVE ID is unique from CVE-2018-0746 and CVE-2018-0747.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Windows kernelBrowse Microsoft Corporation / Windows kernel | CVE List | Windows 10 version 1703. Windows 10 version 1709, and Windows Server, version 1709 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBMicrosoft Windows - 'nt!NtQueryInformationProcess (information class 76_ QueryProcessEnergyValues)' Kernel Stack Memory DisclosureExploitDB exploitby Google Security ResearchNot analyzed1 file
References
51040097vdb entry
http://www.securitytracker.com/id/1040097 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-0745 portal.msrc.microsoft.comConfirmation
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0745 43470exploit
https://www.exploit-db.com/exploits/43470