CVE-2017-11784

LOW

Description

The Microsoft Windows Kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, allows an information disclosure vulnerability when it improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-11765, CVE-2017-11785, and CVE-2017-11814.

References

http://www.securityfocus.com/bid/101147

http://www.securitytracker.com/id/1039526

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11784

Details

Source: MITRE

Published: 2017-10-13

Updated: 2017-10-20

Type: CWE-200

Risk Information

CVSS v2.0

Base Score: 2.1

Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Impact Score: 2.9

Exploitability Score: 3.9

Severity: LOW

CVSS v3.0

Base Score: 5.5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Impact Score: 3.6

Exploitability Score: 1.8

Severity: MEDIUM

Tenable Plugins

View all (5 total)

IDNameProductFamilySeverity
104384KB4042895: Windows 10 October 2017 Cumulative Update (KRACK)NessusWindows : Microsoft Bulletins
critical
103816Windows 2008 October 2017 Multiple Security Updates (KRACK)NessusWindows : Microsoft Bulletins
critical
103750Windows 8.1 and Windows Server 2012 R2 October 2017 Security Updates (KRACK)NessusWindows : Microsoft Bulletins
critical
103748Windows Server 2012 October 2017 Security Updates (KRACK)NessusWindows : Microsoft Bulletins
critical
103746Windows 7 and Windows Server 2008 R2 October 2017 Security Updates (KRACK)NessusWindows : Microsoft Bulletins
critical