SB2018061209 - Denial of service when processing WEBDAV in Micorosft Windows
Published: June 12, 2018
Security Bulletin ID
SB2018061209
Severity
Medium
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Denial of service
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper input validation (CVE-ID: CVE-2018-8175)
The vulnerability allows a remote attacker to perform a denial of service attack.
The vulnerability exists due to an error when Windows NT WEBDAV Minirdr attempts to query a WEBDAV directory. A remote attacker can create a specially crafted web page, trick the victim into opening it, trigger the system to send an SMB request and cause the affected system to crash.
Successful exploitation of the vulnerability may allow an attacker to perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.