Improper input validation in Microsoft Windows and Windows Server - CVE-2018-0961

 

Improper input validation in Microsoft Windows and Windows Server - CVE-2018-0961

Published: May 8, 2018 / Updated: May 8, 2018


Vulnerability identifier: #VU12499
CSH Severity: Medium
CVSS v4: 7.3 [CVSS:4.0/AV:A/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-0961
CWE-ID: CWE-20
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to an input validation error when processing vSMB packet data. An attacker running inside a virtual machine could run a specially crafted application that could cause the Hyper-V host operating system to execute arbitrary code.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable host system.



Affected software

Microsoft Windows
Windows Server

How to mitigate CVE-2018-0961

Install updates from vendor's website.


External References

Related Security Bulletins