CVE-2018-0897 is an information disclosure vulnerability in the Windows kernel affecting numerous versions of Microsoft Windows and Windows Server. This flaw, stemming from how memory addresses are handled, could allow an attacker to gain sensitive information. Rated with a CVSS score of 4.7 (MEDIUM), this vulnerability requires low privileges and high attack complexity, but could lead to significant information disclosure (C:H). Its FAUCET Risk Score is high at 90/100, indicating a notable risk. While not listed in the KEV catalog, an ExploitDB entry (EDB-44310) exists detailing a 64-bit stack memory disclosure. Community discussion and media coverage are present, with one article from BleepingComputer mentioning its fix in a March Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:* | ||
1511CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:* | ||
1607CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:* | ||
1703CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1703:*:*:*:*:*:*:* | ||
1709CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1709:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.