CVE-2018-8444Sensitive Information Exposure in Microsoft Windows 10

Severity
5.9MEDIUMNVD
EPSS
11.4%
top 6.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 13
Latest updateMay 14

Description

An information disclosure vulnerability exists in the way that the Microsoft Server Message Block 2.0 (SMBv2) server handles certain requests, aka "Windows SMB Information Disclosure Vulnerability." This affects Windows Server 2012, Windows 10, Windows 8.1, Windows RT 8.1, Windows Server 2012 R2.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages6 packages

CVEListV5microsoft/windows_server_2012(Server Core installation)
CVEListV5microsoft/windows_server_2012_r2(Server Core installation)
CVEListV5microsoft/windows_1032-bit Systems, x64-based Systems+1
CVEListV5microsoft/windows_8.132-bit systems, x64-based systems+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-hvfj-3jwp-qwrf: An information disclosure vulnerability exists in the way that the Microsoft Server Message Block 22022-05-14
CVEList
CVE-2018-8444: An information disclosure vulnerability exists in the way that the Microsoft Server Message Block 22018-09-13

📋Vendor Advisories

1
Microsoft
Windows SMB Information Disclosure Vulnerability2018-09-11
CVE-2018-8444 — Sensitive Information Exposure | cvebase