CVE-2018-0974 is an information disclosure vulnerability in the Windows kernel affecting multiple versions of Windows and Windows Server. This flaw allows an attacker to retrieve information that could facilitate a Kernel Address Space Layout Randomization (ASLR) bypass. With a CVSS score of 5.5 (Medium), it requires local access and low privileges, but successful exploitation can lead to high confidentiality impact by revealing sensitive kernel memory addresses. While there is no evidence of active exploitation in the wild, a public exploit (EDB-44464) exists that demonstrates a kernel 64-bit stack memory disclosure. The vulnerability has garnered some community attention and media coverage, indicating awareness within the cybersecurity landscape. Despite its medium severity, the potential to bypass ASLR makes it a significant concern for system integrity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:*:*:*:*:*:*:*:* | ||
1511CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:* | ||
1607CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:* | ||
1703CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1703:*:*:*:*:*:*:* | ||
1709CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1709:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.