Improper access control in Microsoft Windows and Windows Server - CVE-2018-8584

 

Improper access control in Microsoft Windows and Windows Server - CVE-2018-8584

Published: October 24, 2018 / Updated: November 14, 2018


Vulnerability identifier: #VU15487
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-8584
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to cause DoS condition on the target system.

The vulnerability exists due to improper access control в Data Sharing Service (dssvc.dll). A local attacker can abuse a new Windows service not checking permissions again, delete OS files or DLLs, replace them with malicious versions and crash the operating system.


Affected software

Microsoft Windows
Windows Server

How to mitigate CVE-2018-8584

Install updates from vendor's website.


External References

Related Security Bulletins