CVE-2018-8476
published 2018-11-14CVE-2018-8476: A remote code execution vulnerability exists in the way that Windows Deployment Services TFTP Server handles objects in memory, aka "Windows Deployment…
PriorityP270critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
63.29%
99.1th percentile
A remote code execution vulnerability exists in the way that Windows Deployment Services TFTP Server handles objects in memory, aka "Windows Deployment Services TFTP Server Remote Code Execution Vulnerability." This affects Windows Server 2012 R2, Windows Server 2008, Windows Server 2012, Windows Server 2019, Windows Server 2016, Windows Server 2008 R2, Windows 10 Servers.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_servers | — | — |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008_r2 | — | — |
| microsoft | windows_server_2008_r2 | — | — |
| microsoft | windows_server_2008_r2 | — | — |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012_r2 | — | — |
| microsoft | windows_server_2016 | — | — |
| microsoft | windows_server_2016 | — | — |
| microsoft | windows_server_2019 | — | — |
| msrc | windows_server_2008_for_32-bit_systems_service_pack_2 | — | — |
| msrc | windows_server_2008_for_itanium-based_systems_service_pack_2 | — | — |
| msrc | windows_server_2008_for_x64-based_systems_service_pack_2 | — | — |
| msrc | windows_server_2008_r2_for_itanium-based_systems_service_pack_1 | — | — |
| msrc | windows_server_2008_r2_for_x64-based_systems_service_pack_1 | — | — |
| msrc | windows_server_2012 | — | — |
| msrc | windows_server_2012_r2 | — | — |
| msrc | windows_server_2016 | — | — |
| msrc | windows_server_2019 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect anomalous TFTP RRQ packets that use both 'blksize' and 'windowsize' options simultaneously — this is the crafted request pattern used to trigger the UAF by populating more than two CacheBlocks before an ACK is received. ↗
- →Monitor for unauthenticated TFTP Read Requests (RRQ) to the Windows Deployment Services server (UDP/69) originating from unexpected or unauthorized hosts on the LAN, as the vulnerability is pre-authentication and requires no credentials. ↗
- →Alert on heap corruption or use-after-free exceptions in wdstftp.dll — specifically when RAX points to freed memory during IOCompletionCallback execution, as this is the crash signature of the vulnerability. ↗
- →Check Point IPS blade signature 'Microsoft Windows Deployment Services TFTP Server Code Execution (CVE-2018-8476)' can be used for network-level detection. ↗
- →Monitor for unusual RPC requests to wdssrv.dll from the same source as TFTP anomalies — the exploit chain involves using the WDS RPC interface (CRpcHandler::OnRecvRequest) as a heap-spray primitive targeting heap bucket size 0x5c-0x78. ↗
- ·The UAF is a race condition — exploitation success depends on server load and timing. A busy server handling large volumes of file read/write requests increases the attacker's chance of winning the race. ↗
- ·The CacheBlock linked list is hard-coded to a maximum of two nodes; exceeding this limit triggers tail deletion and the UAF condition — this is a fixed architectural constraint in the vulnerable wdstftp.dll. ↗
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_msrc8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Windows Deployment Services TFTP Server Remote Code Execution Vulnerability
vendor_msrc·2018-11-13·CVSS 8.1
CVE-2018-8476 [CRITICAL] Windows Deployment Services TFTP Server Remote Code Execution Vulnerability
Windows Deployment Services TFTP Server Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists in the way that Windows Deployment Services TFTP Server handles objects in memory.
An attacker who successfully exploited the vulnerability could execute arbitrary code with elevated permissions on a target system.
To exploit the vulnerability, an attacker could create a specially crafted request, causing Windows to execute arbitrary code with elevated permissions.
The security update addresses the vulnerability by correcting how Windows Deployment Services TFTP Server handles objects in memory.
Microsoft Windows: Microsoft Windows
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exp
GHSA
GHSA-qwwf-66q6-w688: A remote code execution vulnerability exists in the way that Windows Deployment Services TFTP Server handles objects in memory, aka "Windows Deploymen
ghsa_unreviewed·2022-05-13
CVE-2018-8476 [CRITICAL] CWE-119 GHSA-qwwf-66q6-w688: A remote code execution vulnerability exists in the way that Windows Deployment Services TFTP Server handles objects in memory, aka "Windows Deploymen
A remote code execution vulnerability exists in the way that Windows Deployment Services TFTP Server handles objects in memory, aka "Windows Deployment Services TFTP Server Remote Code Execution Vulnerability." This affects Windows Server 2012 R2, Windows Server 2008, Windows Server 2012, Windows Server 2019, Windows Server 2016, Windows Server 2008 R2, Windows 10 Servers.
No detection rules found.
No public exploits indexed.
Checkpoint
PXE Dust: Finding a Vulnerability in Windows Servers Deployment Services
blogs_checkpoint·2019-03-06
CVE-2018-8476 PXE Dust: Finding a Vulnerability in Windows Servers Deployment Services
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
AI Research 2
Android Malware 23
Artificial Intelligence 4
ChatGPT 3
Check Point Research Publications 455
Cloud Security 1
CPRadio 44
Crypto 2
Data & Threat Intelligence 2
Data Analysis 0
Demos 22
Global Cyber Attack Reports 408
How To Guides 13
Ransomware 5
Russo-Ukrainian War 1
Security Report 1
Threat and data analysis 0
Threat Research 174
Web 3.0 Security 11
Wipers 0
## PXE Dust: Finding a Vulnerability in Windows Servers Deployment Services
Research By: Omer Gull
Introduction
Many large organizations use Windows Deployment Services (WDS) to install cus
Qualys
November 2018 Patch Tuesday – 62 Vulns, TFTP Server RCE, Adobe PoC | Qualys
blogs_qualys·2018-11-13·CVSS 9.8
[CRITICAL] November 2018 Patch Tuesday – 62 Vulns, TFTP Server RCE, Adobe PoC | Qualys
This month’s Patch Tuesday addresses 62 vulnerabilities, with 12 of them labeled as Critical. Out of the Criticals, 8 are for the Chakra Scripting Engine used by Microsoft Edge. A Remote Code Execution vulnerability in Windows Deployment Services’ TFTP server is also addressed in this release. Adobe also patched three Important vulnerabilities this month, although there is a PoC exploit available for Adobe Acrobat and Reader.
### Workstation Patches
Browser and Scripting Engine patches should be prioritized for workstation-type devices, meaning any system that is used for email or to access the internet via a browser. This includes multi-user servers that are used as remote desktops for users. Out of the 12 Critical vulnerabilities, 10 can be exploited through browsers or opening malicio
Qualys
November 2018 Patch Tuesday – 62 Vulns, TFTP Server RCE, Adobe PoC
blogs_qualys·2018-11-13·CVSS 9.8
[CRITICAL] November 2018 Patch Tuesday – 62 Vulns, TFTP Server RCE, Adobe PoC
This month’s Patch Tuesday addresses 62 vulnerabilities, with 12 of them labeled as Critical. Out of the Criticals, 8 are for the Chakra Scripting Engine used by Microsoft Edge. A Remote Code Execution vulnerability in Windows Deployment Services’ TFTP server is also addressed in this release. Adobe also patched three Important vulnerabilities this month, although there is a PoC exploit available for Adobe Acrobat and Reader.
## Workstation Patches
Browser and Scripting Engine patches should be prioritized for workstation-type devices, meaning any system that is used for email or to access the internet via a browser. This includes multi-user servers that are used as remote desktops for users. Out of the 12 Critical vulnerabilities, 10 can be exploited through browsers or opening maliciou
Zscaler
Zscaler protects against 15 new vulnerabilities for Microsoft Windows, Internet Explorer, Microsoft Edge and ChakraCore. | Zscaler
blogs_zscaler·CVSS 5.5
[MEDIUM] Zscaler protects against 15 new vulnerabilities for Microsoft Windows, Internet Explorer, Microsoft Edge and ChakraCore. | Zscaler
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
http://www.securityfocus.com/bid/105774http://www.securitytracker.com/id/1042109https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8476https://research.checkpoint.com/2019/pxe-dust-finding-a-vulnerability-in-windows-servers-deployment-services/http://www.securityfocus.com/bid/105774http://www.securitytracker.com/id/1042109https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8476https://research.checkpoint.com/2019/pxe-dust-finding-a-vulnerability-in-windows-servers-deployment-services/
2018-11-14
Published