CVE-2017-8481 is an information disclosure vulnerability in the Microsoft Windows kernel, affecting numerous versions including Windows 7, 8.1, 10, and various Server editions. An authenticated attacker can exploit this flaw by running a specially crafted application to obtain sensitive information. Rated with a CVSS score of 5.0 (Medium), this vulnerability requires local access and user interaction (running the application) to succeed, leading to a high impact on confidentiality. While not actively exploited in the wild according to KEV, an ExploitDB entry (EDB-42242) exists demonstrating kernel stack memory disclosure. Community discussion and media coverage indicate some awareness of this vulnerability, with one article mentioning its fix in a Microsoft Patch Tuesday. Its EPSS score is low, suggesting a low probability of exploitation in the wild despite the available exploit code.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:* | ||
1511CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:* | ||
1607CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:* | ||
1703CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1703:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.