Record summary

CVE-2018-8414 has a selected CVSS score of 8.8 (high); EIP currently links 1 repository PoC. CISA lists CVE-2018-8414 in KEV.

Description

A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths, aka "Windows Shell Remote Code Execution Vulnerability." This affects Windows 10 Servers, Windows 10.

Description source: CVE List

Exploitation context

Known exploitation

CISA KEV
Listed · Mar 25, 2022 · CISA
VulnCheck KEV
Listed · Aug 14, 2018 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Repository PoCs
1

CISA SSVC decision

ExploitationActive
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 7, 2025 · Source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus
CISAVersion data not supplied
CVE ListVersion 1703 for 32-bit Systemsaffected
Version 1703 for x64-based Systemsaffected
Version 1709 for 32-bit Systemsaffected
Version 1709 for x64-based Systemsaffected
Version 1803 for 32-bit Systemsaffected
Version 1803 for x64-based Systemsaffected
CVE Listversion 1709 (Server Core Installation)affected
version 1803 (Server Core Installation)affected

Proofs of concept

1

Repository PoCs

GitHubwhereisr0da/CVE-2018-8414-POCRepository PoCby whereisr0daStars: 21Not analyzed2 files

1.3 KiB

GitHub

PoC details

References

5