#VU14373 Improper input validation in Windows and Windows Server - CVE-2018-8414
Published: August 14, 2018 / Updated: August 14, 2018
Windows
Windows Server
Microsoft
Description
The vulnerability allows a remote attacker to execute arbitrary commands on the target system.
The vulnerability exists due to an error when validating file paths in Windows Shell. A remote attacker can create a specially crafted file, trick the victim into opening it and execute arbitrary system commands on the vulnerable system.