PT-2018-18528 · Microsoft · Windows Server 2016+10

Hungtt28

·

Published

2018-07-10

·

Updated

2019-10-03

·

CVE-2018-8282

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Windows 7 Windows Server 2008 Windows Server 2008 R2 Windows Server 2012 Windows Server 2012 R2 Windows Server 2016 Windows 8.1 Windows RT 8.1 Windows 10 Windows 10 Servers
Description An issue exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. This can lead to an elevation of privilege. Additionally, a denial-of-service condition can be triggered, affecting the system. The issue may involve a child window NULL pointer dereference, potentially allowing privilege escalation.
Recommendations For Windows 7, apply the necessary patch to fix the kernel-mode driver issue. For Windows Server 2008, update the system to handle objects in memory properly. For Windows Server 2008 R2, ensure the kernel-mode driver is updated to the latest version. For Windows Server 2012, apply the patch to resolve the child window NULL pointer dereference issue. For Windows Server 2012 R2, update the system to prevent the denial-of-service condition. For Windows Server 2016, apply the necessary fix to the kernel-mode driver. For Windows 8.1, update the system to handle objects in memory properly. For Windows RT 8.1, ensure the kernel-mode driver is updated to prevent the elevation of privilege. For Windows 10, apply the patch to resolve the child window NULL pointer dereference issue. For Windows 10 Servers, update the system to prevent the denial-of-service condition.

Fix

LPE

DoS

Improper Resource Release

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-8282
ZDI-18-616

Affected Products

Windows
Windows 10
Windows 10 Servers
Windows 7
Windows 8.1
Windows Rt 8.1
Windows Server 2008
Windows Server 2008 R2
Windows Server 2012
Windows Server 2012 R2
Windows Server 2016