#VU6065 Information disclosure in Windows and Windows Server - CVE-2017-0112
Published: March 14, 2017 / Updated: September 14, 2018
Vulnerability identifier: #VU6065
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/U:Clear
CVE-ID: CVE-2017-0112
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
Public exploit is available
Vulnerable software:
Windows
Windows Server
Windows
Windows Server
Software vendor:
Microsoft
Microsoft
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to improper disclosure of memory contents in Windows Uniscribe. A remote unauthenticated attacker can trick the victim into opening a specially crafted document or visiting a malformed web page and gain access to potentially sensitive information.
Successful exploitation of this vulnerability may allow an attacker to gain access to potentially sensitive data.
Remediation
Install updates from vendor's website.