#VU13297 Buffer overflow in Microsoft products - CVE-2018-8231
Published: June 12, 2018 / Updated: August 16, 2022
Windows
Windows Server
Microsoft Internet Information Services (IIS)
Microsoft
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to boundary error within the HTTP Protocol Stack (Http.sys). A remote unauthenticated attacker can send a specially crafted packet to a targeted Http.sys server, trigger memory corruption and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.