Out-of-bounds read in Microsoft Windows and Windows Server - CVE-2018-8637

 

Out-of-bounds read in Microsoft Windows and Windows Server - CVE-2018-8637

Published: December 11, 2018


Vulnerability identifier: #VU16466
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-8637
CWE-ID: CWE-125
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to potentially sensitive information.

The vulnerability exists due to a boundary condition Windows kernel. A local user can run a specially crafted application to read contests from kernel memory and use the information to bypass Kernel Address Space Layout Randomization (KASLR) protection.


Affected software

Microsoft Windows
Windows Server

How to mitigate CVE-2018-8637

Install updates from vendor's website.


External References

Related Security Bulletins