ZeroHour

CVE-2018-8414

KEVmass

File Path Validation RCE in Microsoft Windows Shell (Windows 10 and Server 1703–1803)

CISA: Microsoft Windows Shell Remote Code Execution Vulnerability

CVSS 3.1
8.8 high
EPSS
74%p99
Published
()
KEV added
AI analysis

Microsoft's Windows Shell improperly validates file paths in certain Windows 10 and Windows Server releases, a remote code execution flaw rooted in improper input validation (CWE-20). The flaw is triggered when the shell processes a specially crafted file path, typically requiring the victim to interact with a malicious file, as reflected in the CVSS user-interaction (UI:R) requirement. Successful exploitation lets an attacker execute arbitrary code in the context of the current user, with high impact on confidentiality, integrity, and availability. Affected products are Windows 10 versions 1703, 1709, and 1803 and Windows Server (Semi-Annual Channel) versions 1709 and 1803. The bug was patched in Microsoft's August 2018 Patch Tuesday after being reported as one of two zero-days actively exploited in attacks in the wild, was later added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-25, and EPSS currently estimates a 74% probability of exploitation within 30 days.

What to do: Apply Microsoft's August 2018 security updates or later cumulative updates for Windows 10 1703/1709/1803 and Windows Server 1709/1803, consistent with Microsoft guidance and CISA's KEV required action; because these builds are now legacy, upgrading to a currently supported Windows release is the durable fix. Until patched, treat untrusted files and shortcuts with caution since exploitation requires user interaction. Inventory endpoints for the affected builds to confirm they are fully remediated.

Affected
Microsoft Windows 101703
Microsoft Windows 101709
Microsoft Windows 101803
Microsoft Windows Server (Semi-Annual Channel)1709
Microsoft Windows Server (Semi-Annual Channel)1803
Estimated exposure
mass≈ hundreds of millions of Windows 10 devices at the time of disclosure (builds 1703–1803 were then-current Windows 10 releases); today only residual legacy,… — Public telemetry reported Windows 10's installed base at over 700 million devices around 2018, when builds 1703–1803 were the mainstream feature updates, so this is a mass-scale population that has since contracted to legacy deployments as…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths, aka "Windows Shell Remote Code Execution Vulnerability." This affects Windows 10 Servers, Windows 10.

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1703, windows 10 1709, windows 10 1803, windows server 1709, windows server 1803
Weakness
CWE-20
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news