CVE-2018-8495Path Traversal in Microsoft Windows 10

CWE-22Path Traversal5 documents5 sources
Severity
7.5HIGHNVD
EPSS
59.9%
top 1.73%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 10
Latest updateMay 13

Description

A remote code execution vulnerability exists when Windows Shell improperly handles URIs, aka "Windows Shell Remote Code Execution Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.6 | Impact: 5.9

Affected Packages5 packages

CVEListV5microsoft/windows_10_serversversion 1709 (Server Core Installation), version 1803 (Server Core Installation)+1
CVEListV5microsoft/windows_server_2016(Server Core installation)
NVDmicrosoft/windows1709, 1803+1
CVEListV5microsoft/windows_108 versions+7
NVDmicrosoft/windows_104 versions+3

Patches

🔴Vulnerability Details

2
GHSA
GHSA-mc99-9q9v-9cj5: A remote code execution vulnerability exists when Windows Shell improperly handles URIs, aka "Windows Shell Remote Code Execution Vulnerability2022-05-13
CVEList
CVE-2018-8495: A remote code execution vulnerability exists when Windows Shell improperly handles URIs, aka "Windows Shell Remote Code Execution Vulnerability2018-10-10

🔍Detection Rules

1
Suricata
ET WEB_CLIENT Possible Microsoft Edge Remote Command Execution PoC (CVE-2018-8495)2018-10-15

📋Vendor Advisories

1
Microsoft
Windows Shell Remote Code Execution Vulnerability2018-10-09
CVE-2018-8495 — Path Traversal in Microsoft Windows 10 | cvebase