Privilege escalation in Windows and Windows Server - CVE-2018-8219
Published: June 12, 2018
Vulnerability identifier: #VU13319
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2018-8219
CWE-ID: CWE-264
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vendor: Microsoft
Affected software:
Windows
Windows Server
Windows
Windows Server
Detailed vulnerability description
The vulnerability allows an adjacent attacker to gain elevated privileges on the target system.
The vulnerability exists due to an error when Windows Hyper-V instruction emulation fails to properly enforce privilege levels. An adjacent attacker can gain elevated privileges on a target guest operating system.
How to mitigate CVE-2018-8219
Install updates from vendor's website.