CVE-2018-0828Insufficiently Protected Credentials in Corporation Windows

Severity
7.8HIGHNVD
EPSS
1.0%
top 23.01%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 15
Latest updateMay 13

Description

Windows 10 version 1607 and Windows Server 2016 allow an elevation of privilege vulnerability due to how the MultiPoint management account password is stored, aka "Windows Elevation of Privilege Vulnerability".

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages5 packages

Patches

🔴Vulnerability Details

1
GHSA
GHSA-5vf7-7pjq-2fqj: Windows 10 version 1607 and Windows Server 2016 allow an elevation of privilege vulnerability due to how the MultiPoint management account password is2022-05-13

📋Vendor Advisories

1
Microsoft
Windows Elevation of Privilege Vulnerability2018-02-13

🕵️Threat Intelligence

2
Talos
Microsoft Patch Tuesday - February 20182018-02-13
Talos
Microsoft Patch Tuesday - February 20182018-02-13
CVE-2018-0828 — Insufficiently Protected Credentials | cvebase