CVE-2018-8471Improper Resource Shutdown or Release in Microsoft Windows 10

Severity
7.8HIGHNVD
EPSS
0.9%
top 25.01%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 14
Latest updateMay 13

Description

An elevation of privilege vulnerability exists in the way that the Microsoft RemoteFX Virtual GPU miniport driver handles objects in memory, aka "Microsoft RemoteFX Virtual GPU miniport driver Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows 8.1, Windows 7, Windows Server 2019.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages24 packages

CVEListV5microsoft/windows_server_2016Windows Server 2016
CVEListV5microsoft/windows_server_2019Windows Server 2019
CVEListV5microsoft/windows_732-bit Systems Service Pack 1, x64-based Systems Service Pack 1+1

Patches

🔴Vulnerability Details

1
GHSA
GHSA-j68m-gc9c-h89h: An elevation of privilege vulnerability exists in the way that the Microsoft RemoteFX Virtual GPU miniport driver handles objects in memory, aka "Micr2022-05-13

📋Vendor Advisories

1
Microsoft
Microsoft RemoteFX Virtual GPU miniport driver Elevation of Privilege Vulnerability2018-11-13
CVE-2018-8471 — Improper Resource Shutdown or Release | cvebase