105016vdb entry
http://www.securityfocus.com/bid/105016 CVE-2018-8414
HIGHCISA KEV
Microsoft Windows Shell Remote Code Execution Vulnerability
Record summary
CVE-2018-8414 has a selected CVSS score of 8.8 (high); EIP currently links 1 repository PoC. CISA lists CVE-2018-8414 in KEV.
Description
A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths, aka "Windows Shell Remote Code Execution Vulnerability." This affects Windows 10 Servers, Windows 10.
Description source: CVE List
Exploitation context
Known exploitation
- CISA KEV
- Listed · Mar 25, 2022 · CISA
- VulnCheck KEV
- Listed · Aug 14, 2018 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Repository PoCs
- 1
CISA SSVC decision
ExploitationActive
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 7, 2025 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
WindowsBrowse Microsoft / Windows | CISA | Version data not supplied | |
Windows 10Browse Microsoft / Windows 10 | CVE List | Version 1703 for 32-bit Systems | affected |
| Version 1703 for x64-based Systems | affected | ||
| Version 1709 for 32-bit Systems | affected | ||
| Version 1709 for x64-based Systems | affected | ||
| Version 1803 for 32-bit Systems | affected | ||
| Version 1803 for x64-based Systems | affected | ||
Windows 10 ServersBrowse Microsoft / Windows 10 Servers | CVE List | version 1709 (Server Core Installation) | affected |
| version 1803 (Server Core Installation) | affected | ||
Proofs of concept
1Repository PoCs
GitHubwhereisr0da/CVE-2018-8414-POCRepository PoCby whereisr0daStars: 21Not analyzed2 files
References
51041458vdb entry
http://www.securitytracker.com/id/1041458 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-8414 portal.msrc.microsoft.comConfirmation
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8414 cisa.govGovernment resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-8414