102365vdb entry
http://www.securityfocus.com/bid/102365 CVE-2018-0746
MEDIUM
Microsoft Windows - 'nt!NtQuerySystemInformation (information class 138_ QueryMemoryTopologyInformation)' Kernel Pool Memory Disclosure
Record summary
CVE-2018-0746 has a selected CVSS score of 4.7 (medium); EIP currently links 1 catalogued exploit.
Description
The Windows kernel in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an information disclosure vulnerability due to the way memory addresses are handled, aka "Windows Information Disclosure Vulnerability". This CVE ID is unique from CVE-2018-0745 and CVE-2018-0747.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Windows kernelBrowse Microsoft Corporation / Windows kernel | CVE List | Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBMicrosoft Windows - 'nt!NtQuerySystemInformation (information class 138_ QueryMemoryTopologyInformation)' Kernel Pool Memory DisclosureExploitDB exploitby Google Security ResearchNot analyzed1 file
References
51040097vdb entry
http://www.securitytracker.com/id/1040097 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-0746 portal.msrc.microsoft.comConfirmation
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0746 43471exploit
https://www.exploit-db.com/exploits/43471