CVE-2017-8483 is an information disclosure vulnerability in the Microsoft Windows kernel affecting various versions including Windows 7, 8.1, 10, and Server 2008, 2012, and 2016. An authenticated attacker can exploit this flaw by running a specially crafted application to obtain sensitive information. The vulnerability has a CVSS v3 score of 5.0 (Medium), indicating a local attack vector with low attack complexity, requiring user interaction, and resulting in high confidentiality impact without affecting integrity or availability. Its EPSS score is low, suggesting a minimal likelihood of exploitation. While there is no evidence of active exploitation (not in KEV), an ExploitDB entry exists detailing an out-of-bounds read in ATMFD.DLL. There is no Metasploit or Nuclei support, and community discussion and media coverage are negligible.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:* | ||
1511CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:* | ||
1607CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:* | ||
1703CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1703:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.