CVE-2017-0128 is an information disclosure vulnerability in Uniscribe, affecting Microsoft Windows Vista, Windows 7, and Windows Server 2008. This flaw allows remote attackers to extract sensitive information from process memory by enticing a user to visit a specially crafted website. The vulnerability has a CVSS score of 4.3 (Medium), indicating a low-impact information disclosure. It requires user interaction (UI:R) and can be exploited over a network (AV:N) with low attack complexity (AC:L). The potential impact is limited to confidentiality (C:L) with no integrity or availability impact. While not listed in CISA's KEV catalog, an exploit for a related Uniscribe vulnerability (MS17-011) is available on ExploitDB. There is no evidence of active exploitation, and community discussion and media coverage for CVE-2017-0128 are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_7:*:sp1:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2008:*:sp2:*:*:*:*:*:* | ||
r2CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_vista:*:sp2:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.