CVE-2017-8712 is an information disclosure vulnerability in the Windows Hyper-V component affecting Windows 10 versions 1607 and 1703, and Windows Server 2016. This flaw allows an authenticated user on a guest operating system to potentially gain sensitive information due to improper input validation. With a CVSS score of 5.3 (Medium), exploitation requires high attack complexity and high privileges, but could lead to a complete compromise of confidentiality. There is no evidence of active exploitation, public exploit code, or significant community discussion, though it was addressed in a Microsoft Patch Tuesday update.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1607CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:* | ||
1703CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1703:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.