CVE-2017-11785 is an information disclosure vulnerability in the Microsoft Windows Kernel, affecting numerous Windows versions including Windows 7, 8.1, 10, and various Server editions. The vulnerability arises from improper handling of objects in memory, potentially allowing an attacker to gain sensitive information. Rated with a CVSS score of 5.5 (Medium), this vulnerability has a low attack complexity and requires local user privileges, but can lead to high confidentiality impact. While there is no direct impact on integrity or availability, the information disclosure could facilitate further attacks. Although not actively exploited in the wild or listed on the KEV catalog, a public proof-of-concept exploit exists on ExploitDB. Community discussion and media coverage indicate moderate awareness, suggesting it has received some attention from security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:* | ||
1511CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:* | ||
1607CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:* | ||
1703CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1703:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_7:*:sp1:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.