SB2018061209 - Denial of service when processing WEBDAV in Micorosft Windows 



SB2018061209 - Denial of service when processing WEBDAV in Micorosft Windows

Published: June 12, 2018

Security Bulletin ID SB2018061209
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Improper input validation (CVE-ID: CVE-2018-8175)

The vulnerability allows a remote attacker to perform a denial of service attack.

The vulnerability exists due to an error when Windows NT WEBDAV Minirdr attempts to query a WEBDAV directory. A remote attacker can create a specially crafted web page, trick the victim into opening it, trigger the system to send an SMB request and cause the affected system to crash.

Successful exploitation of the vulnerability may allow an attacker to perform a denial of service (DoS) attack.


Remediation

Install update from vendor's website.