CVE-2018-8115
HIGHWindows Host Compute Service Shim < 0.6.10 - Remote Code Execution via Container Image Import
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-8115. PoCs published by aquasecurity.
AI-analyzed exploit summary This repository contains a Python-based scanner tool designed to detect malicious Docker images exploiting CVE-2018-8115 by checking for path traversal vulnerabilities in layer files. It connects to Docker Hub, fetches image metadata, and analyzes layers for suspicious file paths.
Description
A remote code execution vulnerability exists when the Windows Host Compute Service Shim (hcsshim) library fails to properly validate input while importing a container image, aka "Windows Host Compute Service Shim Remote Code Execution Vulnerability." This affects Windows Host Compute.
Exploits (1)
This repository contains a Python-based scanner tool designed to detect malicious Docker images exploiting CVE-2018-8115 by checking for path traversal vulnerabilities in layer files. It connects to Docker Hub, fetches image metadata, and analyzes layers for suspicious file paths.
References (3)
Scores
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H