PT-2018-2087 · Microsoft · Windows Server 2016+12

James Forshaw

·

Published

2018-10-09

·

Updated

2020-08-24

·

CVE-2018-8411

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Windows 7 Windows Server 2012 R2 Windows RT 8.1 Windows Server 2008 Windows Server 2019 Windows Server 2012 Windows 8.1 Windows Server 2016 Windows Server 2008 R2 Windows 10 Windows 10 Servers
Description The issue is related to errors in access control, allowing an attacker to run processes with elevated privileges using a specially crafted application. This is due to NTFS improperly checking access.
Recommendations For Windows 7, apply the necessary patch to fix the NTFS access control issue. For Windows Server 2012 R2, update the system to resolve the elevation of privilege vulnerability. For Windows RT 8.1, install the latest security update to address the issue. For Windows Server 2008, apply the relevant patch to fix the access control errors. For Windows Server 2019, update the NTFS configuration to properly check access. For Windows Server 2012, install the necessary security update to resolve the vulnerability. For Windows 8.1, apply the patch to fix the elevation of privilege issue. For Windows Server 2016, update the system to address the access control errors. For Windows Server 2008 R2, install the latest security update to resolve the vulnerability. For Windows 10, apply the necessary patch to fix the NTFS access control issue. For Windows 10 Servers, update the system to resolve the elevation of privilege vulnerability.

Exploit

Fix

LPE

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-00038
CVE-2018-8411

Affected Products

Ntfs
Windows
Windows 10
Windows 10 Servers
Windows 7
Windows 8.1
Windows Rt 8.1
Windows Server 2008
Windows Server 2008 R2
Windows Server 2012
Windows Server 2012 R2
Windows Server 2016
Windows Server 2019