CVE-2017-8680 is an information disclosure vulnerability in the Windows kernel (Win32k component) affecting Windows 7, 8.1, RT 8.1, Server 2008, and Server 2012. This flaw arises from improper handling of objects in memory, potentially allowing an attacker to gain sensitive information. With a CVSS score of 5.5 (Medium), this vulnerability requires local access and low privileges, but no user interaction, to achieve high confidentiality impact. The EPSS score and FAUCET Risk Score indicate a significant likelihood of exploitation and high overall risk. While not listed on the CISA KEV catalog, an exploit for this vulnerability (EDB-42741) is publicly available on ExploitDB. The CVE has garnered notable community discussion and media coverage, suggesting awareness and potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:* | ||
r2CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:itanium:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.