CVE-2018-8414
A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths, aka "Windows Shell Remote Code Execution Vulnerability." This affects Windows 10 Servers, Windows 10.
- Affected products
- Windows, Windows 10, Windows 10 Servers, Windows Shell
- Microsoft Windows 10 1703
- All versions
- Microsoft Windows 10 1709
- All versions
- Microsoft Windows 10 1803
- All versions
- Microsoft Windows Server 1709
- All versions
- Microsoft Windows Server 1803
- All versions
- Fix
- Available
- CVSS 2.0
- 9.3 HIGH
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 74.0% (99th percentile)
- Weakness
- CWE-20
- NVD status
- Analyzed
- Published
- 2018-08-15
CVE-2018-8414 at NVD
1 known exploit for CVE-2018-8414
Proof-of-concept code and exploit modules indexed by Sploitus