CVE-2018-8208: High severity Microsoft Windows 10 vulnerability
An elevation of privilege vulnerability exists in Windows when Desktop Bridge does not properly manage the virtual registry, aka "Windows Desktop Bridge Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8214.
Affected Software
Remediation
Event History
Frequently Asked Questions
Who is exposed to this vulnerability?
Systems running the affected Windows 10 or Windows Server 2016 products are exposed when Desktop Bridge is in use. Exploitation requires local access and low-privileged access to the affected system.
What level of access does an attacker need?
The CVSS vector indicates local access and low privileges are required, with high attack complexity and no user interaction required. Successful exploitation can result in elevation of privilege and high impacts to confidentiality, integrity, and availability.
Is a patch available?
Yes. A patch is available for this vulnerability.