LOW · 2.6

CVE-2017-0096

Hyper-V in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1, Windows Server 2012 Gold and R2; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows gue...

Vulnerability Description

Hyper-V in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1, Windows Server 2012 Gold and R2; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows guest OS users to obtain sensitive information from host OS memory via a crafted application, aka "Hyper-V Information Disclosure Vulnerability."

CVSS Score

2.6

LOW

CVSS:3.0/AV:A/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N
Attack Vector
ADJACENT_NETWORK
Attack Complexity
HIGH
Privileges Required
HIGH
User Interaction
NONE
Scope
CHANGED
Confidentiality
LOW
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
MicrosoftWindows 10-
MicrosoftWindows 7All versions
MicrosoftWindows 8.1All versions
MicrosoftWindows Server 2008All versions
MicrosoftWindows Server 2012-
MicrosoftWindows Server 2016All versions
MicrosoftWindows VistaAll versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2017-0096?

CVE-2017-0096 is a vulnerability with a CVSS score of 2.6 (LOW). Hyper-V in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1, Windows Server 2012 Gold and R2; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows gue...

How severe is CVE-2017-0096?

CVE-2017-0096 has been rated LOW with a CVSS base score of 2.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2017-0096?

Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Windows 10, Microsoft Windows 7, Microsoft Windows 8.1, Microsoft Windows Server 2008, Microsoft Windows Server 2012.