← All CVEs

CVE-2018-8414

high · 8.8Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions.

Added 2022-03-25Remediation due 2022-04-15

A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths, aka "Windows Shell Remote Code Execution Vulnerability." This affects Windows 10 Servers, Windows 10.

8.8
CVSS
74.0%
EPSS (exploit prob.)
99th
EPSS percentile
2018-08-15
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Weaknesses

CWE-20

Affected products

VendorProductAffected versions
microsoftwindows_10_1703all versions
microsoftwindows_10_1703all versions
microsoftwindows_10_1709all versions
microsoftwindows_10_1709all versions
microsoftwindows_10_1803all versions
microsoftwindows_10_1803all versions
microsoftwindows_server_1709all versions
microsoftwindows_server_1803all versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2018-8414