SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2018-8414

Microsoft Windows Shell Remote Code Execution Vulnerability

KEVHIGH 8.8EPSS 74.0%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 15 April 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths, aka "Windows Shell Remote Code Execution Vulnerability." This affects Windows 10 Servers, Windows 10.

CVSS 3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
73.97% probability · 99th percentile
CISA KEV
Listed 25 March 2022 · due 15 April 2022
Weakness
CWE-20
Affected
microsoft/windows 10 1703 · microsoft/windows 10 1709 · microsoft/windows 10 1803 · microsoft/windows server 1709 · microsoft/windows server 1803
Source
secure@microsoft.com

CISA notes

Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2018-8414

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.