CVE-2017-11768

low
Published 2017-11-15 · Modified 2026-05-13
CVSS v3
2.5
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS v2
1.9
VIR risk
2.5

Description

Windows Media Player in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016, and Windows Server, version 1709 allows remote attackers to test for the presence of files on disk via a specially crafted application. due to the way Windows Media Player discloses file information, aka "Windows Media Player Information Disclosure Vulnerability."

Predictions

Exploit likelihood
27%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: secure@microsoft.com — https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11768

OS impact

OSVersionStatusFixed in
windows windows-not-affected
windows windows1511not-affected
windows windows1607not-affected
windows windows1703not-affected
windows windows1709not-affected
windows windowsr2not-affected
windows windowsnot-affected

Application impact

VendorProductVersionsFixed
windows microsoftwindows_media_player-

References

CWEs

CWE-200

Verify integrity in audit chain (admin only). AS-IS.