CVE-2018-8142: Medium severity Microsoft Windows 10 vulnerability
Published May 21, 2018
·Updated
A security feature bypass exists when Windows incorrectly validates kernel driver signatures, aka "Windows Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-1035.
Affected Software
5 affected components
Microsoft Windows 10=1607
Microsoft Windows 10=1703
Microsoft Windows 10=1709
Microsoft Windows Server 2016
Microsoft Windows Server 2016=1709
Remediation
Event History
May 21, 2018
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
DescriptionWeakness
Data Sourced
via NVD·01:29 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The CVSS vector indicates local access and low privileges are required. No user interaction is required.
2
Which systems are identified as affected?
The affected products listed are Microsoft Windows 10 and Microsoft Windows Server 2016. The description also identifies Windows 10 Servers.
3
What should teams do to remediate the vulnerability?
A patch is available. Apply the vendor-provided patch to affected systems.