CVE-2017-11852: Microsoft Windows 7

Medium severity, CVSS 4.7. EPSS: 2.2% chance of exploitation in the next 30 days.

Microsoft GDI Component in Windows 7 SP1 and Windows Server 2008 SP2 and R2 SP1 allows an attacker to log on to an affected system and run a specially crafted application to compromise the user's system, due improperly disclosing kernel memory addresses, aka "Windows GDI Information Disclosure Vulnerability".

Affected products

  • Microsoft Windows 7: affected versions not specified
  • Microsoft Windows Server 2008: affected versions not specified; version r2 only

Published 2017-11-15. Last modified 2026-06-17.