Описание
Windows Themes Information Disclosure Vulnerability
FAQ
According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to win a race condition.
What type of information could be disclosed by this vulnerability?
Exploiting this vulnerability could allow the disclosure of initialized or uninitialized memory in the process heap.
Обновления
Продукт | Статья | Обновление |
---|---|---|
Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) | ||
Windows Server 2008 R2 for x64-based Systems Service Pack 1 | ||
Windows Server 2012 | ||
Windows Server 2012 (Server Core installation) | ||
Windows Server 2012 R2 | ||
Windows Server 2012 R2 (Server Core installation) | ||
Windows 10 for 32-bit Systems | ||
Windows 10 for x64-based Systems | ||
Windows Server 2016 | ||
Windows 10 Version 1607 for 32-bit Systems |
Показывать по
10
Возможность эксплуатации
Publicly Disclosed
No
Exploited
No
Latest Software Release
Exploitation Less Likely
DOS
N/A
EPSS
Процентиль: 28%
0.00095
Низкий
4.7 Medium
CVSS3
Связанные уязвимости
CVSS3: 4.7
github
больше 1 года назад
Windows Themes Information Disclosure Vulnerability
CVSS3: 4.7
fstec
больше 1 года назад
Уязвимость компонента Themes (темы Windows) операционной системы Windows, позволяющая нарушителю раскрыть защищаемую информацию
EPSS
Процентиль: 28%
0.00095
Низкий
4.7 Medium
CVSS3