Exploitation Summary
EIP tracks 2 public exploits for CVE-2018-8214. PoCs published by Google Security Research, guwudoor.
AI-analyzed exploit summary This exploit leverages an incomplete fix for CVE-2018-0880 in Windows Desktop Bridge, allowing arbitrary file creation as SYSTEM via manipulation of the virtual registry's Helium directory. The PoC renames the Helium folder, recreates it as a mount point, and drops symbolic links to achieve privilege escalation.
Description
An elevation of privilege vulnerability exists in Windows when Desktop Bridge does not properly manage the virtual registry, aka "Windows Desktop Bridge Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8208.
Exploits (2)
This exploit leverages an incomplete fix for CVE-2018-0880 in Windows Desktop Bridge, allowing arbitrary file creation as SYSTEM via manipulation of the virtual registry's Helium directory. The PoC renames the Helium folder, recreates it as a mount point, and drops symbolic links to achieve privilege escalation.
References (4)
Scores
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H