CVE-2018-8450
published 2018-11-14CVE-2018-8450: A remote code execution vulnerability exists when Windows Search handles objects in memory, aka "Windows Search Remote Code Execution Vulnerability." This…
PriorityP260high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
16.08%
96.5th percentile
A remote code execution vulnerability exists when Windows Search handles objects in memory, aka "Windows Search Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
Affected
46 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10_servers | — | — |
| microsoft | windows_10_servers | — | — |
| microsoft | windows_7 | — | — |
| microsoft | windows_7 | — | — |
| microsoft | windows_8.1 | — | — |
| microsoft | windows_8.1 | — | — |
| microsoft | windows_rt_8.1 | — | — |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008_r2 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Exploit vector involves specially crafted messages sent to the Windows Search service; monitor for anomalous or malformed inbound requests to the Windows Search service process. ↗
- →In enterprise environments, exploitation can be triggered remotely over SMB by an authenticated attacker; monitor for unusual SMB connections targeting hosts running Windows Search, particularly from unexpected authenticated sources. ↗
- ·Exploitation is rated 'More Likely' for both latest and older software releases per Microsoft's exploitability index, meaning detection and patching should be prioritized even though no in-the-wild exploitation was confirmed at time of disclosure. ↗
- ·The vulnerability affects a wide range of Windows versions; ensure detection coverage spans all affected platforms: Windows 7, Windows 8.1, Windows RT 8.1, Windows 10, Windows Server 2008/2008 R2, Windows Server 2012/2012 R2, and Windows Server 2016. ↗
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_msrc7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fmvr-h35x-827f: A remote code execution vulnerability exists when Windows Search handles objects in memory, aka "Windows Search Remote Code Execution Vulnerability
ghsa_unreviewed·2022-05-13
CVE-2018-8450 [HIGH] CWE-404 GHSA-fmvr-h35x-827f: A remote code execution vulnerability exists when Windows Search handles objects in memory, aka "Windows Search Remote Code Execution Vulnerability
A remote code execution vulnerability exists when Windows Search handles objects in memory, aka "Windows Search Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
Microsoft
Windows Search Remote Code Execution Vulnerability
vendor_msrc·2018-11-13·CVSS 7.5
CVE-2018-8450 [HIGH] Windows Search Remote Code Execution Vulnerability
Windows Search Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists when Windows Search handles objects in memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
To exploit the vulnerability, the attacker could send specially crafted messages to the Windows Search service. An attacker with access to a target computer could exploit this vulnerability to elevate privileges and take control of the computer. Additionally, in an enterprise scenario, a remote authenticated attacker could remotely trigger the vulnerability through an SMB connection and then take control of a target compu
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/105797http://www.securitytracker.com/id/1042117https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8450http://www.securityfocus.com/bid/105797http://www.securitytracker.com/id/1042117https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8450
2018-11-14
Published