CVE-2017-0259: Microsoft Windows 10

Medium severity, CVSS 4.7. EPSS: 9.7% chance of exploitation in the next 30 days.

The Windows kernel in Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows authenticated attackers to obtain sensitive information via a specially crafted document, aka "Windows Kernel Information Disclosure Vulnerability," a different vulnerability than CVE-2017-0175, CVE-2017-0220, and CVE-2017-0258.

Affected products

  • Microsoft Windows 10: affected versions not specified; version 1511 only; version 1607 only; version 1703 only
  • Microsoft Windows 8.1: any version
  • Microsoft Windows Rt 8.1: affected versions not specified
  • Microsoft Windows Server 2012: version r2 only
  • Microsoft Windows Server 2016: affected versions not specified

Published 2017-05-12. Last modified 2026-06-17.