CVE-2018-8414
KEVmassFile Path Validation RCE in Microsoft Windows Shell (Windows 10 and Server 1703–1803)
CISA: Microsoft Windows Shell Remote Code Execution Vulnerability
Microsoft's Windows Shell improperly validates file paths in certain Windows 10 and Windows Server releases, a remote code execution flaw rooted in improper input validation (CWE-20). The flaw is triggered when the shell processes a specially crafted file path, typically requiring the victim to interact with a malicious file, as reflected in the CVSS user-interaction (UI:R) requirement. Successful exploitation lets an attacker execute arbitrary code in the context of the current user, with high impact on confidentiality, integrity, and availability. Affected products are Windows 10 versions 1703, 1709, and 1803 and Windows Server (Semi-Annual Channel) versions 1709 and 1803. The bug was patched in Microsoft's August 2018 Patch Tuesday after being reported as one of two zero-days actively exploited in attacks in the wild, was later added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-25, and EPSS currently estimates a 74% probability of exploitation within 30 days.
What to do: Apply Microsoft's August 2018 security updates or later cumulative updates for Windows 10 1703/1709/1803 and Windows Server 1709/1803, consistent with Microsoft guidance and CISA's KEV required action; because these builds are now legacy, upgrading to a currently supported Windows release is the durable fix. Until patched, treat untrusted files and shortcuts with caution since exploitation requires user interaction. Inventory endpoints for the affected builds to confirm they are fully remediated.
| Microsoft Windows 10 | 1703 |
| Microsoft Windows 10 | 1709 |
| Microsoft Windows 10 | 1803 |
| Microsoft Windows Server (Semi-Annual Channel) | 1709 |
| Microsoft Windows Server (Semi-Annual Channel) | 1803 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths, aka "Windows Shell Remote Code Execution Vulnerability." This affects Windows 10 Servers, Windows 10.
- Affected
- Microsoft Windows
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- windows 10 1703, windows 10 1709, windows 10 1803, windows server 1709, windows server 1803
- Weakness
- CWE-20
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H