CVE-2018-8169: High severity Microsoft Windows 10 vulnerability
An elevation of privilege vulnerability exists when the (Human Interface Device) HID Parser Library driver improperly handles objects in memory, aka "HIDParser Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this vulnerability?
The attacker needs local access and low privileges on the affected Windows system. No user interaction is required.
What could successful exploitation allow?
Successful exploitation could allow elevation of privilege, with high impact to confidentiality, integrity, and availability.
Which systems should be prioritized for review?
Review systems running the listed affected Windows families: Windows 7, Windows 8.1, Windows RT 8.1, Windows 10, and Windows Server 2008, 2008 R2, 2012, 2012 R2, or 2016.