CVE-2018-0842
published 2018-02-15CVE-2018-0842: Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows…
PriorityP430high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
1.03%
59.4th percentile
Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allow an elevation of privilege vulnerability due to how objects in memory are handled, aka "Windows Kernel Elevation of Privilege Vulnerability".
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_embedded_compact | < 6.0 | 6.0 |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2016 | — | — |
| microsoft_corporation | windows | — | — |
| msrc | windows_10 | — | — |
| msrc | windows_10_version_1511 | — | — |
| msrc | windows_10_version_1607 | — | — |
| msrc | windows_10_version_1703 | — | — |
| msrc | windows_10_version_1709 | — | — |
| msrc | windows_7 | — | — |
| msrc | windows_8.1 | — | — |
| msrc | windows_rt_8.1 | — | — |
| msrc | windows_server_2008 | — | — |
| msrc | windows_server_2008_r2 | — | — |
| msrc | windows_server_2012 | — | — |
| msrc | windows_server_2012_r2 | — | — |
| msrc | windows_server_2016 | — | — |
| msrc | windows_server_version_1709 | — | — |
CVSS provenance
nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
vendor_msrc6.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-695j-jf36-x34x: Windows 7 SP1, Windows 8
ghsa_unreviewed·2022-05-13
CVE-2018-0842 [HIGH] GHSA-695j-jf36-x34x: Windows 7 SP1, Windows 8
Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allow an elevation of privilege vulnerability due to how objects in memory are handled, aka "Windows Kernel Elevation of Privilege Vulnerability".
Microsoft
Windows Kernel Elevation of Privilege Vulnerability
vendor_msrc·2018-02-13·CVSS 6.7
CVE-2018-0842 [HIGH] Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application to take control of an affected system.
The update addresses the vulnerability by correcting how the Windows kernel handles objects in memory.
Windows Kernel: Windows Kernel
Impact: Elevation of Privilege
Exploit Status: Publicly Disclosed:No;Exploited:No;L
No detection rules found.
No public exploits indexed.
Talos
Microsoft Patch Tuesday - February 2018
blogs_talos·2018-02-13·CVSS 3.1
[LOW] Microsoft Patch Tuesday - February 2018
Microsoft Patch Tuesday - February 2018
Today Microsoft has released its monthly set of security advisories for vulnerabilities that have been identified and addressed in various products. This month's advisory release addresses 54 new vulnerabilities with 14 of them rated critical, 38 of them rated important, and 2 of them rated Moderate. These vulnerabilities impact Outlook, Edge, Scripting Engine, App Container, Windows, and more.
## Critical VulnerabilitiesThis month, Microsoft is addressing 14 vulnerabilities that are rated "critical." Talos believes one of these are notable and require prompt attention, detailed below.
CVE-2018-0852 - Microsoft Outlook Memory Corruption Vulnerability
A remote code execution vulnerability has been identified in Microsoft Outlook when the software
Talos
Microsoft Patch Tuesday - February 2018
blogs_talos·2018-02-13·CVSS 3.1
[LOW] Microsoft Patch Tuesday - February 2018
## Microsoft Patch Tuesday - February 2018
Microsoft Patch Tuesday - February 2018
Today Microsoft has released its monthly set of security advisories for vulnerabilities that have been identified and addressed in various products. This month's advisory release addresses 54 new vulnerabilities with 14 of them rated critical, 38 of them rated important, and 2 of them rated Moderate. These vulnerabilities impact Outlook, Edge, Scripting Engine, App Container, Windows, and more.
## Critical Vulnerabilities This month, Microsoft is addressing 14 vulnerabilities that are rated "critical." Talos believes one of these are notable and require prompt attention, detailed below.
CVE-2018-0852 - Microsoft Outlook Memory Corruption Vulnerability
A remote code execution vulnerability has been ident
Zscaler
Zscaler protects against 11 new vulnerabilities for Internet
blogs_zscaler·CVSS 7.8
[HIGH] Zscaler protects against 11 new vulnerabilities for Internet
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Bugzilla
CVE-2017-15131 xdg-user-dirs, gnome-session: Xsession creation of XDG user directories does not honor system umask policy
bugzilla·2017-05-24·CVSS 7.8
CVE-2017-15131 [HIGH] CVE-2017-15131 xdg-user-dirs, gnome-session: Xsession creation of XDG user directories does not honor system umask policy
CVE-2017-15131 xdg-user-dirs, gnome-session: Xsession creation of XDG user directories does not honor system umask policy
It was found that system umask policy is not being honored when creating XDG user directories, since Xsession sources xdg-user-dirs.sh before setting umask policy.
Product bug:
https://bugzilla.redhat.com/show_bug.cgi?id=1412762
Discussion:
Created gnome-session tracking bugs for this issue:
Affects: fedora-all [bug 1455095]
Created xdg-user-dirs tracking bugs for this issue:
Affects: fedora-all [bug 1455096]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2018:0842 https://access.redhat.com/errata/RHSA-2018:0842
http://www.securityfocus.com/bid/102946http://www.securitytracker.com/id/1040371https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0842http://www.securityfocus.com/bid/102946http://www.securitytracker.com/id/1040371https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0842
2018-02-15
Published