CVE-2017-0115 is an information disclosure vulnerability in Uniscribe, a text rendering engine in Microsoft Windows Vista SP2, Server 2008 SP2/R2 SP1, and Windows 7 SP1. This flaw allows remote attackers to extract sensitive data from process memory by luring users to a specially crafted website. With a CVSS score of 4.3 (Medium), this vulnerability requires user interaction (UI:R) to exploit, as a victim must visit a malicious site. While the attack complexity is low (AC:L), successful exploitation could lead to the disclosure of confidential information (C:L). There is no evidence of active exploitation in the wild, nor is it listed in CISA's KEV catalog. However, public exploit code exists on ExploitDB (EDB-41655), indicating a potential for future exploitation. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_7:*:sp1:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2008:*:sp2:*:*:*:*:*:* | ||
r2CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_vista:*:sp2:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.