FAQ
According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do? This attack requires a admin user on the client to connect to a malicious server and then take specific actions which could result in information disclosure.
FAQ
According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability? The attacker must have permissions to access the target domain environment to be able to exploit this vulnerability.
FAQ-Information Disclosure-iSNS
What type of information could be disclosed by this vulnerability? An attacker who successfully exploited this vulnerability could view heap memory from a privileged process running on the server.