#VU15867 Input validation error in Microsoft products - CVE-2018-8415

 

#VU15867 Input validation error in Microsoft products - CVE-2018-8415

Published: November 13, 2018


Vulnerability identifier: #VU15867
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2018-8415
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Windows
Windows Server
PowerShell Core
Software vendor:
Microsoft

Description

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to insufficient validation of user-supplied input within PowerShell files. A remote attacker can create a specially crafted PowerShell file, trick the victim into opening it and execute unlogged code on the target system with privileges of the current user.


Remediation

Install updates from vendor's website.

External links