CVE-2017-8472: Microsoft Windows 7

Medium severity, CVSS 5.0. EPSS: 3.4% chance of exploitation in the next 30 days.

Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, and Windows Server 2012 allow an authenticated attacker to run a specially crafted application when the Windows kernel improperly initializes objects in memory, aka "Win32k Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8470, CVE-2017-8471, CVE-2017-8473, CVE-2017-8475, CVE-2017-8477, and CVE-2017-8484.

Affected products

  • Microsoft Windows 7: affected versions not specified
  • Microsoft Windows Server 2008: affected versions not specified; version r2 only
  • Microsoft Windows Server 2012: affected versions not specified

Published 2017-06-15. Last modified 2026-06-17.