CVE-2018-8414

A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths, aka "Windows Shell Remote Code Execution Vulnerability." This affects Windows 10 Servers, Windows 10.
References
Link Resource
http://www.securityfocus.com/bid/105016 Broken Link Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1041458 Broken Link Third Party Advisory VDB Entry
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8414 Patch Vendor Advisory
http://www.securityfocus.com/bid/105016 Broken Link Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1041458 Broken Link Third Party Advisory VDB Entry
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8414 Patch Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:microsoft:windows_10_1703:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_1703:-:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_1709:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_1709:-:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_1803:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_1803:-:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_server_1709:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_1803:-:*:*:*:*:*:x64:*

History

04 Apr 2025, 20:28

Type Values Removed Values Added
CPE cpe:2.3:o:microsoft:windows_server:1709:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server:1803:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10:1709:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10:1703:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10:1803:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10_1709:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_1709:-:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_1803:-:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_1803:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_1803:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_1703:-:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_1703:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_1709:-:*:*:*:*:*:x64:*
First Time Microsoft windows 10 1709
Microsoft windows Server 1803
Microsoft windows 10 1803
Microsoft windows 10 1703
Microsoft windows Server 1709
References () http://www.securityfocus.com/bid/105016 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/105016 - Broken Link, Third Party Advisory, VDB Entry
References () http://www.securitytracker.com/id/1041458 - Third Party Advisory, VDB Entry () http://www.securitytracker.com/id/1041458 - Broken Link, Third Party Advisory, VDB Entry

Information

Published : 2018-08-15 17:29

Updated : 2025-04-04 20:28


NVD link : CVE-2018-8414

Mitre link : CVE-2018-8414

CVE.ORG link : CVE-2018-8414


JSON object : View

Products Affected

microsoft

  • windows_server_1803
  • windows_server_1709
  • windows_10_1709
  • windows_10_1703
  • windows_10_1803
CWE
CWE-20

Improper Input Validation