#VU15271 Privilege escalation in Windows and Windows Server - CVE-2018-8411
Published: October 9, 2018 / Updated: October 16, 2018
Windows
Windows Server
Microsoft
Description
The vulnerability allows a local attacker to gain elevated privileges on the target system.
The vulnerability exists due to the FSCTL_FIND_FILES_BY_SID control code within NTFS filesystem improperly checks for access permissions to list a directory, when Quotas are configured. A local unprivileged user can run a specially crafted application and gain elevated privileges on the system.