PT-2018-2087 · Microsoft · Windows Server 2016+12
James Forshaw
·
Published
2018-10-09
·
Updated
2020-08-24
·
CVE-2018-8411
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Windows 7
Windows Server 2012 R2
Windows RT 8.1
Windows Server 2008
Windows Server 2019
Windows Server 2012
Windows 8.1
Windows Server 2016
Windows Server 2008 R2
Windows 10
Windows 10 Servers
Description
The issue is related to errors in access control, allowing an attacker to run processes with elevated privileges using a specially crafted application. This is due to NTFS improperly checking access.
Recommendations
For Windows 7, apply the necessary patch to fix the NTFS access control issue.
For Windows Server 2012 R2, update the system to resolve the elevation of privilege vulnerability.
For Windows RT 8.1, install the latest security update to address the issue.
For Windows Server 2008, apply the relevant patch to fix the access control errors.
For Windows Server 2019, update the NTFS configuration to properly check access.
For Windows Server 2012, install the necessary security update to resolve the vulnerability.
For Windows 8.1, apply the patch to fix the elevation of privilege issue.
For Windows Server 2016, update the system to address the access control errors.
For Windows Server 2008 R2, install the latest security update to resolve the vulnerability.
For Windows 10, apply the necessary patch to fix the NTFS access control issue.
For Windows 10 Servers, update the system to resolve the elevation of privilege vulnerability.
Exploit
Fix
LPE
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ntfs
Windows
Windows 10
Windows 10 Servers
Windows 7
Windows 8.1
Windows Rt 8.1
Windows Server 2008
Windows Server 2008 R2
Windows Server 2012
Windows Server 2012 R2
Windows Server 2016
Windows Server 2019