CVE-2018-8115

HIGH

Windows Host Compute Service Shim < 0.6.10 - Remote Code Execution via Container Image Import

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2018-8115. PoCs published by aquasecurity.

AI-analyzed exploit summary This repository contains a Python-based scanner tool designed to detect malicious Docker images exploiting CVE-2018-8115 by checking for path traversal vulnerabilities in layer files. It connects to Docker Hub, fetches image metadata, and analyzes layers for suspicious file paths.

Description

A remote code execution vulnerability exists when the Windows Host Compute Service Shim (hcsshim) library fails to properly validate input while importing a container image, aka "Windows Host Compute Service Shim Remote Code Execution Vulnerability." This affects Windows Host Compute.

Exploits (1)

nomisec SCANNER 7 stars
by aquasecurity · poc
https://github.com/aquasecurity/scan-cve-2018-8115

This repository contains a Python-based scanner tool designed to detect malicious Docker images exploiting CVE-2018-8115 by checking for path traversal vulnerabilities in layer files. It connects to Docker Hub, fetches image metadata, and analyzes layers for suspicious file paths.

Classification
Scanner 95%
Attack Type
Other
Complexity
Moderate
Reliability
Reliable
Target: Docker images (CVE-2018-8115)
No auth needed
Prerequisites: Docker Hub access · Python environment
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/104061
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1040842

Scores

CVSS v3 8.6
EPSS 0.0352
EPSS Percentile 87.8%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Details

CWE
CWE-20
Status published
Products (1)
microsoft/windows_host_compute_service_shim < 0.6.10
Published May 02, 2018
Tracked Since Feb 18, 2026