#VU14401 Privilege escalation in Windows Server and Windows - CVE-2018-8342
Published: August 14, 2018 / Updated: August 14, 2018
Windows Server
Windows
Microsoft
Description
The vulnerability allows a local attacker to gain elevated privileges on the target system.
The vulnerability exists in the Network Driver Interface Specification (NDIS) due to ndis.sys fails to check the length of a buffer prior to copying memory to it. A local attacker can run a specially crafted application and trigger memory corruption to gain SYSTEM privileges.