Information disclosure in Microsoft Windows and Windows Server - CVE-2018-0902

 

Information disclosure in Microsoft Windows and Windows Server - CVE-2018-0902

Published: March 13, 2018 / Updated: March 13, 2018


Vulnerability identifier: #VU11050
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-0902
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to obtain potentially sensitive information.

The vulnerability exists due to an error in the Cryptography Next Generation (CNG) kernel-mode driver (cng.sys). A remote attacker can trick the victim into running a specially crafted application that is designed to cause CNG to improperly validate impersonation levels and gain access to potentially sensitive information.


Affected software

Microsoft Windows
Windows Server

How to mitigate CVE-2018-0902

Install updates from vendor's website.


External References

Related Security Bulletins