CVE-2018-0971 Information
Description
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve information that could lead to a Kernel Address Space Layout Randomization (ASLR) bypass aka \Windows Kernel Information Disclosure Vulnerability.\ This affects Windows 7 Windows Server 2012 R2 Windows RT 8.1 Windows Server 2008 Windows Server 2012 Windows 8.1 Windows Server 2016 Windows Server 2008 R2 Windows 10 Windows 10 Servers. This CVE ID is unique from CVE-2018-0887 CVE-2018-0960 CVE-2018-0968 CVE-2018-0969 CVE-2018-0970 CVE-2018-0972 CVE-2018-0973 CVE-2018-0974 CVE-2018-0975.
CVSS Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Reference
http://www.securityfocus.com/bid/103648 http://www.securitytracker.com/id/1040657 https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0971 https://www.exploit-db.com/exploits/44461/
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
NONE
Base Severity
5.5
Share on: