#VU11029 Improper input validation in Windows and Windows Server - CVE-2018-0886
Published: March 13, 2018 / Updated: June 17, 2021
Windows
Windows Server
Microsoft
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to an error when validation authentication requests in Credential Security Support Provider protocol (CredSSP). A remote unauthenticated attacker with ability to perform a Man-in-the-Middle (MitM) attack can execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.