CVE-2018-8251: High severity Microsoft Windows 10 vulnerability
A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka "Media Foundation Memory Corruption Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
Affected Software
Remediation
Event History
Frequently Asked Questions
What must an attacker do to exploit this vulnerability?
The CVSS vector indicates the attack can be delivered over a network without prior privileges, but exploitation requires user interaction. The vulnerability has high attack complexity.
Which systems should be prioritized for remediation?
Prioritize affected Windows endpoints and servers that use Windows Media Foundation, including Windows 7, Windows 8.1, Windows 10, Windows RT 8.1, Windows Server 2008 R2, Windows Server 2012, Windows Server 2012 R2, and Windows Server 2016. Successful exploitation can affect confidentiality, integrity, and availability.
Is a fix available?
Yes. A patch is available for this vulnerability.