CVE-2018-8592
published 2018-11-14CVE-2018-8592: An elevation of privilege vulnerability exists in Windows 10 version 1809 when installed from physical media (USB, DVD, etc, aka "Windows Elevation Of…
PriorityP426medium6.4CVSS 3.0
AVPACHPRNUINSUCHIHAH
EPSS
1.25%
66.0th percentile
An elevation of privilege vulnerability exists in Windows 10 version 1809 when installed from physical media (USB, DVD, etc, aka "Windows Elevation Of Privilege Vulnerability." This affects Windows 10, Windows Server 2019.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_server_2019 | — | — |
| msrc | windows_10_version_1809_for_32-bit_systems | — | — |
| msrc | windows_10_version_1809_for_arm64-based_systems | — | — |
| msrc | windows_10_version_1809_for_x64-based_systems | — | — |
| msrc | windows_server_2019 | — | — |
CVSS provenance
nvdv3.06.4MEDIUMCVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
vendor_msrc6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Windows Elevation Of Privilege Vulnerability
vendor_msrc·2018-11-13·CVSS 6.4
CVE-2018-8592 [MEDIUM] Windows Elevation Of Privilege Vulnerability
Windows Elevation Of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists in Windows 10 version 1809 when installed from physical media (USB, DVD, etc.) with the “keep nothing” option selected during installation. Successful exploitation of the vulnerability could allow an attacker to gain local access to an affected system.
To exploit the vulnerability, an attacker would need physical access to the console of the affected system.
The update addresses the vulnerability by changing built-in account behavior after the setup process completes.
For recommendations on managing the local administrator accounts, please see Implementing Least-Privilege Administrative Models
FAQ: What versions of Windows 10 version 1809 builds are affected by this vulnerability?
Aff
GHSA
GHSA-qc85-45h3-w2fg: An elevation of privilege vulnerability exists in Windows 10 version 1809 when installed from physical media (USB, DVD, etc, aka "Windows Elevation Of
ghsa_unreviewed·2022-05-13
CVE-2018-8592 [MEDIUM] GHSA-qc85-45h3-w2fg: An elevation of privilege vulnerability exists in Windows 10 version 1809 when installed from physical media (USB, DVD, etc, aka "Windows Elevation Of
An elevation of privilege vulnerability exists in Windows 10 version 1809 when installed from physical media (USB, DVD, etc, aka "Windows Elevation Of Privilege Vulnerability." This affects Windows 10, Windows Server 2019.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/105809http://www.securitytracker.com/id/1042126https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8592http://www.securityfocus.com/bid/105809http://www.securitytracker.com/id/1042126https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8592
2018-11-14
Published