102360vdb entry
http://www.securityfocus.com/bid/102360 CVE-2018-0752
HIGH
Microsoft Windows - NtImpersonateAnonymousToken LPAC to Non-LPAC Privilege Escalation
Record summary
CVE-2018-0752 has a selected CVSS score of 7.8 (high); EIP currently links 1 catalogued exploit.
Description
The Windows Kernel API in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way the Kernel API enforces permissions, aka "Windows Elevation of Privilege Vulnerability". This CVE ID is unique from CVE-2018-0751.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Windows kernelBrowse Microsoft Corporation / Windows kernel | CVE List | Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBMicrosoft Windows - NtImpersonateAnonymousToken LPAC to Non-LPAC Privilege EscalationExploitDB exploitby Google Security ResearchNot analyzed1 file
References
51040095vdb entry
http://www.securitytracker.com/id/1040095 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-0752 portal.msrc.microsoft.comConfirmation
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0752 43516exploit
https://www.exploit-db.com/exploits/43516