PT-2018-1794 · Microsoft · Windows Server 2016+8
Omer Gull
·
Published
2018-11-13
·
Updated
2020-02-13
·
CVE-2018-8476
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Windows Server versions prior to the fixed version
Windows Server 2012 R2
Windows Server 2008
Windows Server 2012
Windows Server 2019
Windows Server 2016
Windows Server 2008 R2
Windows 10 Servers
Description
A remote code execution issue exists due to the way the Windows Deployment Services TFTP Server handles objects in memory. This allows remote attackers to execute arbitrary code on the system by sending a specially crafted request. The vulnerability can be exploited by remote attackers, potentially leading to the execution of arbitrary code.
Recommendations
For Windows Server 2012 R2, update to a version that includes the fix for this issue.
For Windows Server 2008, consider applying a workaround or configuration change to mitigate the risk until a patch is available.
For Windows Server 2012, restrict access to the TFTP Server until a patch is available.
For Windows Server 2019, Windows Server 2016, Windows Server 2008 R2, and Windows 10 Servers, update to a version that includes the fix for this issue.
As a temporary workaround, consider disabling the TFTP Server service until a patch is available.
Fix
RCE
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows
Windows 10 Servers
Windows Deployment Services Tftp Server
Windows Server 2008
Windows Server 2008 R2
Windows Server 2012
Windows Server 2012 R2
Windows Server 2016
Windows Server 2019