VulnerabilityModified
CVE-2018-8506
An Information Disclosure vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory, aka "Microsoft Windows Codecs Library Information Disclosure Vulnerability." This affects Windows 10 Servers, Windows 10, Windows…
MEDIUM 5.5EPSS 4.36%
Does this matter?
Lower severity and a low EPSS score (4.36%). Track it; it rarely justifies an emergency change on its own.
Description
An Information Disclosure vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory, aka "Microsoft Windows Codecs Library Information Disclosure Vulnerability." This affects Windows 10 Servers, Windows 10, Windows Server 2019.
- CVSS 3.0
- 5.5 MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
- EPSS
- 4.36% probability · 91th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/windows 10 · microsoft/windows server 2016 · microsoft/windows server 2019
- Source
- secure@microsoft.com
References
- http://www.securityfocus.com/bid/105466Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041833Third Party Advisory, VDB Entry
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8506Patch, Vendor Advisory
- http://www.securityfocus.com/bid/105466Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041833Third Party Advisory, VDB Entry
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8506Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.