CVE-2018-0971 is an information disclosure vulnerability in the Windows kernel affecting various versions of Windows, including Windows 7, 8.1, 10, and several Windows Server editions. This vulnerability could allow an attacker to retrieve memory information, potentially leading to a Kernel Address Space Layout Randomization (ASLR) bypass. Rated with a CVSS score of 5.5 (Medium), the vulnerability requires local access and low privileges (AV:L/PR:L) but has a high impact on confidentiality (C:H) by disclosing sensitive kernel memory details. Its EPSS score is low, suggesting a limited likelihood of exploitation. While not listed in CISA's KEV catalog, an exploit (EDB-44461) demonstrating 64-bit stack memory disclosure is available on ExploitDB. Community discussion and media coverage are minimal, indicating limited widespread attention or active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:*:*:*:*:*:*:*:* | ||
1511CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:* | ||
1607CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:* | ||
1703CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1703:*:*:*:*:*:*:* | ||
1709CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1709:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.