CVE-2018-0828
published 2018-02-15CVE-2018-0828: Windows 10 version 1607 and Windows Server 2016 allow an elevation of privilege vulnerability due to how the MultiPoint management account password is stored…
PriorityP338high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
1.04%
59.7th percentile
Windows 10 version 1607 and Windows Server 2016 allow an elevation of privilege vulnerability due to how the MultiPoint management account password is stored, aka "Windows Elevation of Privilege Vulnerability".
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft_corporation | windows | — | — |
| msrc | windows_10_version_1607_for_32-bit_systems | — | — |
| msrc | windows_10_version_1607_for_x64-based_systems | — | — |
| msrc | windows_server_2016 | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
vendor_msrc6.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Windows Elevation of Privilege Vulnerability
vendor_msrc·2018-02-13·CVSS 6.6
CVE-2018-0828 [HIGH] Windows Elevation of Privilege Vulnerability
Windows Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists in Microsoft Windows when the MultiPoint management account password is improperly secured. An attacker who successfully exploited this vulnerability could run arbitrary code with elevated privileges.
To exploit this vulnerability, an attacker must first log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability.
The security update addresses the vulnerability by correcting how the Multipoint management account password is stored.
Microsoft Windows: Microsoft Windows
Impact: Elevation of Privilege
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploi
GHSA
GHSA-5vf7-7pjq-2fqj: Windows 10 version 1607 and Windows Server 2016 allow an elevation of privilege vulnerability due to how the MultiPoint management account password is
ghsa_unreviewed·2022-05-13
CVE-2018-0828 [HIGH] CWE-522 GHSA-5vf7-7pjq-2fqj: Windows 10 version 1607 and Windows Server 2016 allow an elevation of privilege vulnerability due to how the MultiPoint management account password is
Windows 10 version 1607 and Windows Server 2016 allow an elevation of privilege vulnerability due to how the MultiPoint management account password is stored, aka "Windows Elevation of Privilege Vulnerability".
No detection rules found.
No public exploits indexed.
Talos
Microsoft Patch Tuesday - February 2018
blogs_talos·2018-02-13·CVSS 3.1
[LOW] Microsoft Patch Tuesday - February 2018
Microsoft Patch Tuesday - February 2018
Today Microsoft has released its monthly set of security advisories for vulnerabilities that have been identified and addressed in various products. This month's advisory release addresses 54 new vulnerabilities with 14 of them rated critical, 38 of them rated important, and 2 of them rated Moderate. These vulnerabilities impact Outlook, Edge, Scripting Engine, App Container, Windows, and more.
## Critical VulnerabilitiesThis month, Microsoft is addressing 14 vulnerabilities that are rated "critical." Talos believes one of these are notable and require prompt attention, detailed below.
CVE-2018-0852 - Microsoft Outlook Memory Corruption Vulnerability
A remote code execution vulnerability has been identified in Microsoft Outlook when the software
Talos
Microsoft Patch Tuesday - February 2018
blogs_talos·2018-02-13·CVSS 3.1
[LOW] Microsoft Patch Tuesday - February 2018
## Microsoft Patch Tuesday - February 2018
Microsoft Patch Tuesday - February 2018
Today Microsoft has released its monthly set of security advisories for vulnerabilities that have been identified and addressed in various products. This month's advisory release addresses 54 new vulnerabilities with 14 of them rated critical, 38 of them rated important, and 2 of them rated Moderate. These vulnerabilities impact Outlook, Edge, Scripting Engine, App Container, Windows, and more.
## Critical Vulnerabilities This month, Microsoft is addressing 14 vulnerabilities that are rated "critical." Talos believes one of these are notable and require prompt attention, detailed below.
CVE-2018-0852 - Microsoft Outlook Memory Corruption Vulnerability
A remote code execution vulnerability has been ident
http://www.securityfocus.com/bid/102935http://www.securitytracker.com/id/1040373https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0828http://www.securityfocus.com/bid/102935http://www.securitytracker.com/id/1040373https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0828
2018-02-15
Published