PT-2018-2037 · Microsoft · Windows Server 2019+3

Wayne Low

·

Published

2018-12-11

·

Updated

2019-01-04

·

CVE-2018-8612

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Windows Server 2016 Windows 10 Windows Server 2019 Windows 10 Servers
Description A Denial Of Service issue exists due to the failure of the Connected User Experiences and Telemetry Service to validate certain function values. This can be exploited by an attacker to cause a denial of service using a specially crafted application, potentially allowing a local attacker to disrupt the system. The vulnerability is related to improper handling of objects in memory.
Recommendations For Windows Server 2016, update to a version that includes the fix for this issue. For Windows 10, update to a version that includes the fix for this issue. For Windows Server 2019, update to a version that includes the fix for this issue. For Windows 10 Servers, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the Connected User Experiences and Telemetry Service to minimize the risk of exploitation.

Fix

DoS

RCE

Improper Resource Release

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2018-01653
CVE-2018-8612

Affected Products

Windows
Windows 10
Windows Server 2016
Windows Server 2019