CVE-2017-8706

medium

Description

The Windows Hyper-V component on Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability when it fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8707, CVE-2017-8711, CVE-2017-8712, and CVE-2017-8713.

References

http://www.securityfocus.com/bid/100789

http://www.securitytracker.com/id/1039317

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8706

Details

Source: MITRE

Published: 2017-09-13

Updated: 2017-09-21

Type: CWE-200

Risk Information

CVSS v2

Base Score: 1.9

Vector: AV:L/AC:M/Au:N/C:P/I:N/A:N

Impact Score: 2.9

Exploitability Score: 3.4

Severity: LOW

CVSS v3

Base Score: 5.3

Vector: CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N

Impact Score: 4

Exploitability Score: 0.8

Severity: MEDIUM