PT-2018-18528 · Microsoft · Windows Server 2016+10

Hungtt28

·

Publicado

2018-07-10

·

Atualizado

2019-10-03

·

CVE-2018-8282

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Windows 7 Windows Server 2008 Windows Server 2008 R2 Windows Server 2012 Windows Server 2012 R2 Windows Server 2016 Windows 8.1 Windows RT 8.1 Windows 10 Windows 10 Servers
Description An issue exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. This can lead to an elevation of privilege. Additionally, a denial-of-service condition can be triggered, affecting the system. The issue may involve a child window NULL pointer dereference, potentially allowing privilege escalation.
Recommendations For Windows 7, apply the necessary patch to fix the kernel-mode driver issue. For Windows Server 2008, update the system to handle objects in memory properly. For Windows Server 2008 R2, ensure the kernel-mode driver is updated to the latest version. For Windows Server 2012, apply the patch to resolve the child window NULL pointer dereference issue. For Windows Server 2012 R2, update the system to prevent the denial-of-service condition. For Windows Server 2016, apply the necessary fix to the kernel-mode driver. For Windows 8.1, update the system to handle objects in memory properly. For Windows RT 8.1, ensure the kernel-mode driver is updated to prevent the elevation of privilege. For Windows 10, apply the patch to resolve the child window NULL pointer dereference issue. For Windows 10 Servers, update the system to prevent the denial-of-service condition.

Correção

LPE

DoS

Improper Resource Release

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-8282
ZDI-18-616

Produtos afetados

Windows
Windows 10
Windows 10 Servers
Windows 7
Windows 8.1
Windows Rt 8.1
Windows Server 2008
Windows Server 2008 R2
Windows Server 2012
Windows Server 2012 R2
Windows Server 2016