CVE-2017-0057
DNS client in Microsoft Windows 8.1; Windows Server 2012 R2, Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 fails to properly process DNS queries, which allows remote attackers to obtain sensitive information via (1) convincing…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 14.0%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
DNS client in Microsoft Windows 8.1; Windows Server 2012 R2, Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 fails to properly process DNS queries, which allows remote attackers to obtain sensitive information via (1) convincing a workstation user to visit an untrusted webpage or (2) tricking a server into sending a DNS query to a malicious DNS server, aka "Windows DNS Query Information Disclosure Vulnerability."
- CVSS 3.0
- 4.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
- EPSS
- 13.96% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- microsoft/windows 10 · microsoft/windows 8.1 · microsoft/windows rt 8.1 · microsoft/windows server 2012 · microsoft/windows server 2016
- Source
- secure@microsoft.com
References
- http://www.securityfocus.com/bid/96695Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1038001
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0057Patch, Vendor Advisory
- http://www.securityfocus.com/bid/96695Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1038001
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0057Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.