102354vdb entry
http://www.securityfocus.com/bid/102354 CVE-2018-0748
HIGH
Microsoft Windows - NTFS Owner/Mandatory Label Privilege Bypass
Record summary
CVE-2018-0748 has a selected CVSS score of 7.8 (high); EIP currently links 1 catalogued exploit.
Description
The Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way memory addresses are handled, aka "Windows Elevation of Privilege Vulnerability".
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Windows kernelBrowse Microsoft Corporation / Windows kernel | CVE List | Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBMicrosoft Windows - NTFS Owner/Mandatory Label Privilege BypassExploitDB exploitby Google Security ResearchNot analyzed1 file
References
61040095vdb entry
http://www.securitytracker.com/id/1040095 95cnsec.com
https://95cnsec.com/windows-kernel-cve-2018-0748-exploit.html nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-0748 portal.msrc.microsoft.comConfirmation
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0748 43514exploit
https://www.exploit-db.com/exploits/43514