CVE-2018-0952
published 2018-08-15CVE-2018-0952: An Elevation of Privilege vulnerability exists when Diagnostics Hub Standard Collector allows file creation in arbitrary locations, aka "Diagnostic Hub…
PriorityP351high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EXPLOIT
EPSS
6.23%
92.8th percentile
An Elevation of Privilege vulnerability exists when Diagnostics Hub Standard Collector allows file creation in arbitrary locations, aka "Diagnostic Hub Standard Collector Elevation Of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Microsoft Visual Studio, Windows 10 Servers.
Affected
39 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_visual_studio | — | — |
| microsoft | microsoft_visual_studio | — | — |
| microsoft | microsoft_visual_studio | — | — |
| microsoft | visual_studio_2017 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10_servers | — | — |
| microsoft | windows_10_servers | — | — |
| microsoft | windows_server_2016 | — | — |
| microsoft | windows_server_2016 | — | — |
| microsoft | windows_server_2016 | — | — |
| msrc | microsoft_visual_studio_2015_update_3 | — | — |
| msrc | microsoft_visual_studio_2017 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
pathC:\Users\Bob\AppData\Local\Temp\Microsoft\F12\perftools\visualprofiler\c13851b2-b1e1-438f-bf73-949df897f1bf.1.m.etl↗
- →Monitor for mount point creation targeting \RPC Control\ object directory combined with symlink creation redirecting ETL filenames to paths under C:\Windows\System32\, which is the core exploitation primitive for this CVE. ↗
- →Detect unexpected DLL files appearing in C:\Windows\System32 or C:\Windows\System32\DiagSvcs with .etl-style GUID-based filenames (e.g., matching pattern <GUID>.1.m.etl or .dll), written by the DiagnosticsHub Standard Collector Service (DiagnosticsHub.StandardCollector.Runtime.dll). ↗
- →Alert on processes spawned as SYSTEM from DiagnosticsHub Standard Collector Service context, particularly notepad.exe or other unexpected child processes, as the PoC demonstrates SYSTEM-level code execution via DLL loading. ↗
- →Detect OpLock usage on ETL files in the scratch path (e.g., under %TEMP%\Microsoft\F12\perftools\visualprofiler\) combined with file content replacement, which is the TOCTOU race condition exploitation technique used in this attack. ↗
- →Monitor for Diagnostics Hub sessions configured with the specific hardcoded GUID c13851b2-b1e1-438f-bf73-949df897f1bf as the session ID, which is the PoC's fixed exploitation session identifier. ↗
- ·The scratch directory used in the exploit must be a path the attacker user has write permissions to; the vulnerability arises because the CommitPackage copy operation does NOT impersonate the client, unlike the initial file/folder creation steps. ↗
- ·The PoC requires the NtApiDotNet library and is delivered as a Visual Studio solution with a C++ DLL payload project and a C# exploit project; defenders should look for this tooling combination on endpoints. ↗
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_msrc6.7MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g92w-m5cw-jw9w: An Elevation of Privilege vulnerability exists when Diagnostics Hub Standard Collector allows file creation in arbitrary locations, aka "Diagnostic Hu
ghsa_unreviewed·2022-05-13
CVE-2018-0952 [HIGH] GHSA-g92w-m5cw-jw9w: An Elevation of Privilege vulnerability exists when Diagnostics Hub Standard Collector allows file creation in arbitrary locations, aka "Diagnostic Hu
An Elevation of Privilege vulnerability exists when Diagnostics Hub Standard Collector allows file creation in arbitrary locations, aka "Diagnostic Hub Standard Collector Elevation Of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Microsoft Visual Studio, Windows 10 Servers.
Microsoft
Diagnostic Hub Standard Collector Elevation of Privilege Vulnerability
vendor_msrc·2018-08-14·CVSS 6.7
CVE-2018-0952 [HIGH] Diagnostic Hub Standard Collector Elevation of Privilege Vulnerability
Diagnostic Hub Standard Collector Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector or the Visual Studio Standard Collector allows file creation in arbitrary locations.
To exploit the vulnerability, an attacker would first have to log on to the system.
An attacker could then run a specially crafted application that could exploit the vulnerability and take control of an affected system.
The update addresses the vulnerability by not permitting Diagnostics Hub Standard Collector or the Visual Studio Standard Collector to create files in arbitrary locations.
Windows Diagnostic Hub: Windows Diagnostic Hub
Impact: Elevation of Privilege
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software
No detection rules found.
Talos
Microsoft Tuesday August 2018
blogs_talos·2018-08-14·CVSS 9.8
[CRITICAL] Microsoft Tuesday August 2018
## Microsoft Tuesday August 2018
Microsoft released its monthly set of security advisories today for vulnerabilities that have been identified and addressed in various products. This month's advisory release addresses 62 new vulnerabilities, 20 of which are rated “critical,” 38 that are rated “important,” one that is rated moderate and one that is rated as low severity. These vulnerabilities impact Windows Operating System, Edge and Internet Explorer, along with several other products.
In addition to the 60 vulnerabilities referenced above, Microsoft has also released a critical update advisory, ADV180020 which addresses the vulnerabilities described in the Adobe Flash Security Bulletin APSB18-25.
## Critical Vulnerabilities
This month, Microsoft is addressing 20 vulnerabilities that a
Talos
Microsoft Tuesday August 2018
blogs_talos·2018-08-14·CVSS 9.8
[CRITICAL] Microsoft Tuesday August 2018
Microsoft released its monthly set of security advisories today for vulnerabilities that have been identified and addressed in various products. This month's advisory release addresses 62 new vulnerabilities, 20 of which are rated “critical,” 38 that are rated “important,” one that is rated moderate and one that is rated as low severity. These vulnerabilities impact Windows Operating System, Edge and Internet Explorer, along with several other products.
In addition to the 60 vulnerabilities referenced above, Microsoft has also released a critical update advisory, ADV180020 which addresses the vulnerabilities described in the Adobe Flash Security Bulletin APSB18-25.
### Critical Vulnerabilities
This month, Microsoft is addressing 20 vulnerabilities that are rated "critical." Talos believ
http://www.securityfocus.com/bid/105048http://www.securitytracker.com/id/1041466https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0952https://www.exploit-db.com/exploits/45244/http://www.securityfocus.com/bid/105048http://www.securitytracker.com/id/1041466https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0952https://www.exploit-db.com/exploits/45244/
2018-08-15
Published