CVE-2018-8206: High severity Microsoft Windows 10 vulnerability
A denial of service vulnerability exists when Windows improperly handles File Transfer Protocol (FTP) connections, aka "Windows FTP Server Denial of Service Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
Affected Software
Remediation
Event History
Frequently Asked Questions
What access does an attacker need to trigger the denial of service?
The CVSS vector indicates network-based exploitation with low attack complexity, no privileges required, and no user interaction required. An attacker can target a reachable affected Windows FTP service remotely.
What is the expected impact if exploitation succeeds?
The documented impact is denial of service. The CVSS vector reports high availability impact and no confidentiality or integrity impact.
Which systems should be prioritized for remediation?
Prioritize affected Windows systems that provide FTP connectivity and are reachable by untrusted networks. The affected platforms listed include Windows 7, Windows 8.1, Windows RT 8.1, Windows 10, and Windows Server 2008, 2008 R2, 2012, 2012 R2, and 2016.
Is a fix available?
Yes. A patch is available for this vulnerability.