PT-2018-1794 · Microsoft · Windows Server 2016+8

Omer Gull

·

Published

2018-11-13

·

Updated

2020-02-13

·

CVE-2018-8476

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Windows Server versions prior to the fixed version Windows Server 2012 R2 Windows Server 2008 Windows Server 2012 Windows Server 2019 Windows Server 2016 Windows Server 2008 R2 Windows 10 Servers
Description A remote code execution issue exists due to the way the Windows Deployment Services TFTP Server handles objects in memory. This allows remote attackers to execute arbitrary code on the system by sending a specially crafted request. The vulnerability can be exploited by remote attackers, potentially leading to the execution of arbitrary code.
Recommendations For Windows Server 2012 R2, update to a version that includes the fix for this issue. For Windows Server 2008, consider applying a workaround or configuration change to mitigate the risk until a patch is available. For Windows Server 2012, restrict access to the TFTP Server until a patch is available. For Windows Server 2019, Windows Server 2016, Windows Server 2008 R2, and Windows 10 Servers, update to a version that includes the fix for this issue. As a temporary workaround, consider disabling the TFTP Server service until a patch is available.

Fix

RCE

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2018-01394
CVE-2018-8476

Affected Products

Windows
Windows 10 Servers
Windows Deployment Services Tftp Server
Windows Server 2008
Windows Server 2008 R2
Windows Server 2012
Windows Server 2012 R2
Windows Server 2016
Windows Server 2019