CVE-2018-0826: High severity Microsoft Windows 10 vulnerability
Windows Storage Services in Windows 10 versions 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way objects are handled in memory, aka "Windows Storage Services Elevation of Privilege Vulnerability".
Affected Software
Remediation
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker needs local access to an affected system and must already have low-privileged access. The CVSS vector indicates no user interaction is required, but exploitation has high attack complexity.
Which systems are affected?
Affected Windows 10 releases are versions 1511, 1607, 1703, and 1709. Windows Server 2016 and Windows Server, version 1709 are also listed as affected.
What is the impact of successful exploitation?
Successful exploitation can elevate privileges and affect the confidentiality, integrity, and availability of the affected system. The CVSS vector rates all three impacts as high.
What should administrators do?
Apply the available patch for CVE-2018-0826 to affected systems. The provided data does not specify an alternative mitigation if patching cannot be performed immediately.