Remote code execution in Windows and Windows Server - CVE-2018-0883
Published: March 13, 2018 / Updated: March 13, 2018
Windows
Windows Server
Detailed vulnerability description
The weakness exists due to improper validation of file copy destinations by Windows Shell. A remote attacker can trick the victim into opening a specially crafted file and execute arbitrary code with privileges of the current user.
Successful exploitation of the vulnerability may result in system compromise.