PT-2018-18528 · Microsoft · Windows Server 2016+10
Hungtt28
·
Published
2018-07-10
·
Updated
2019-10-03
·
CVE-2018-8282
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Windows 7
Windows Server 2008
Windows Server 2008 R2
Windows Server 2012
Windows Server 2012 R2
Windows Server 2016
Windows 8.1
Windows RT 8.1
Windows 10
Windows 10 Servers
Description
An issue exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. This can lead to an elevation of privilege. Additionally, a denial-of-service condition can be triggered, affecting the system. The issue may involve a child window NULL pointer dereference, potentially allowing privilege escalation.
Recommendations
For Windows 7, apply the necessary patch to fix the kernel-mode driver issue.
For Windows Server 2008, update the system to handle objects in memory properly.
For Windows Server 2008 R2, ensure the kernel-mode driver is updated to the latest version.
For Windows Server 2012, apply the patch to resolve the child window NULL pointer dereference issue.
For Windows Server 2012 R2, update the system to prevent the denial-of-service condition.
For Windows Server 2016, apply the necessary fix to the kernel-mode driver.
For Windows 8.1, update the system to handle objects in memory properly.
For Windows RT 8.1, ensure the kernel-mode driver is updated to prevent the elevation of privilege.
For Windows 10, apply the patch to resolve the child window NULL pointer dereference issue.
For Windows 10 Servers, update the system to prevent the denial-of-service condition.
Fix
LPE
DoS
Improper Resource Release
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows
Windows 10
Windows 10 Servers
Windows 7
Windows 8.1
Windows Rt 8.1
Windows Server 2008
Windows Server 2008 R2
Windows Server 2012
Windows Server 2012 R2
Windows Server 2016