CVE-2017-8688
CVE-2017-8688
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 3.7%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
13 Sep 2017Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Windows GDI+ on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, allows information disclosure by the way it discloses kernel memory addresses, aka "Windows GDI+ Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8684 and CVE-2017-8685.
Affected products
Microsoft Corporation · Windows GDI+Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →