CVE-2017-8488 is an information disclosure vulnerability affecting the kernel in various Microsoft Windows operating systems, including Windows 7, 8.1, 10, and Server 2008/2012/2016. An authenticated attacker can exploit this flaw by running a specially crafted application to obtain sensitive information. Rated with a CVSS score of 5.0 (MEDIUM), this vulnerability requires local access and user interaction (UI:R) to achieve high confidentiality impact (C:H) without affecting integrity or availability. The attack complexity is low, making it relatively easy to exploit once an attacker has authenticated access. While not listed in CISA's KEV catalog, an exploit (EDB-42212) demonstrating a kernel mountmgr pool memory disclosure has been published on ExploitDB. Community discussion and media coverage indicate some awareness, with one article noting it was fixed in a Microsoft Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:* | ||
r2CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:itanium:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.