Security restrictions bypass in Microsoft Windows and Windows Server - CVE-2018-8253

 

Security restrictions bypass in Microsoft Windows and Windows Server - CVE-2018-8253

Published: August 14, 2018 / Updated: August 14, 2018


Vulnerability identifier: #VU14407
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-8253
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to bypass lockscreen.

The vulnerability exists within Microsoft Cortana code that allows arbitrary website browsing on the lockscreen. A user with physical access to device can access vimctim's browser and steal browser stored passwords or log on to websites as another user.

Successful exploitation of the vulnerability requires access to the console and the system must have Microsoft Cortana assistance enabled.

Affected software

Microsoft Windows
Windows Server

How to mitigate CVE-2018-8253

Install updates from vendor's website.


External References

Related Security Bulletins