First published: Thu Jun 14 2018(Updated: )
A remote code execution vulnerability exists when HTTP Protocol Stack (Http.sys) improperly handles objects in memory, aka "HTTP Protocol Stack Remote Code Execution Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows 10 | ||
Microsoft Windows 10 | =1607 | |
Microsoft Windows 10 | =1703 | |
Microsoft Windows 10 | =1709 | |
Microsoft Windows 10 | =1803 | |
Microsoft Windows Server 1803 | ||
Microsoft Windows Server 2016 | ||
Microsoft Windows Server 2016 | =1709 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-8231 is rated as critical due to its ability to allow remote code execution on affected systems.
To fix CVE-2018-8231, you should apply the latest security updates provided by Microsoft for your affected Windows versions.
CVE-2018-8231 affects Windows Server 2016 and multiple versions of Windows 10, including 1607, 1703, 1709, and 1803.
An attacker can exploit CVE-2018-8231 by sending specially crafted HTTP requests to a vulnerable server, potentially allowing remote code execution.
Yes, CVE-2018-8231 can be exploited remotely over the network if the affected service is exposed.