← לוח פגיעויות

CVE-2018-8414

גבוהה 8.8 מנוצלת בשטח (KEV)

ניצול פעיל מאומת — קטלוג CISA KEV

שם
Microsoft Windows Shell Remote Code Execution Vulnerability
נוסף לקטלוג
יעד טיפול (פדרלי)
פעולה נדרשת
Apply updates per vendor instructions.

תיאור (מקור, אנגלית)

A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths, aka "Windows Shell Remote Code Execution Vulnerability." This affects Windows 10 Servers, Windows 10.

מדדים

CVSS 3.1
8.8 (HIGH) מקור הציון: NVD CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS — סבירות ניצול
74% (אחוזון 100) נכון ל-25/7/2026
CWE
CWE-20

מוצרים מושפעים

microsoft: windows 10 1703; microsoft: windows 10 1709; microsoft: windows 10 1803; microsoft: windows server 1709; microsoft: windows server 1803

קישורים