Description
Multiple serious vulnerabilities were found in Microsoft Windows. Malicious users can exploit these vulnerabilities to obtain sensitive information, bypass security restrictions, cause denial of service.
Below is a complete list of vulnerabilities:
- Multiple vulnerabilities in Windows kernel can be exploited locally via a specially crafted application to gain privileges or obtain sensitive information;
- Multiple security bypass vulnerabilities in Device Guard can be exploited locally to bypass security restrictions;
- Improper handling of objects in memory in Microsoft WordPad can be exploited locally via a specially designed document to bypass security restrictions;
- Improper handling of objects in memory in Microsoft Windows can be exploited locally via a specially designed application to cause denial of service;
- An incorrect permissions enforcing in Windows Kernel API can be exploited locally via a specially crafted application to gain privileges;
- An incorrect DNS responses handling in DNSAPI.dll can be exploited remotely via a specially designed DNS request to cause demial of service;
- An incorrect Windows Sandbox configuration can be exploited locally via a specially designed application to gain privileges;
- Improper FTP connections handling in Windows can be exploited remotely via a specially designed query to cause denial of service.
Original advisories
- CVE-2018-8314
- CVE-2018-8222
- CVE-2018-8307
- CVE-2018-8309
- CVE-2018-8313
- CVE-2018-8304
- CVE-2018-8308
- CVE-2018-8206
Exploitation
Malware exists for this vulnerability. Usually such malware is classified as Exploit. More details.
Related products
- Microsoft-Windows
- Microsoft-Windows-Server-2003-Enterprise-Edition
- Microsoft-Windows-Server-2003-Standard-Edition
- Microsoft-Windows-Server-2003-Web-Edition
- Microsoft-Windows-Server-2012
- Microsoft-Windows-8
- Microsoft-Windows-7
- Microsoft-Windows-Server-2008
- Microsoft-Windows-Server-2003
- Microsoft-Windows-10
CVE list
- CVE-2018-8282 high
- CVE-2018-8314 warning
- CVE-2018-8222 warning
- CVE-2018-8307 high
- CVE-2018-8309 warning
- CVE-2018-8313 high
- CVE-2018-8304 high
- CVE-2018-8308 critical
- CVE-2018-8206 critical
KB list
- 4338824
- 4338830
- 4338820
- 4338815
- 4338825
- 4338814
- 4338829
- 4338819
- 4338826
- 4345421
- 4345419
- 4338816
- 4345455
- 4338831
- 4345420
- 4345424
- 4345425
- 4345418
Read more
Find out the statistics of the vulnerabilities spreading in your region on statistics.securelist.com
Found an inaccuracy in the description of this vulnerability? Let us know!