CVE-2018-0883

Description

Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, Windows Server 2016 and Windows Server, version 1709 allows a remote code execution vulnerability due to how file copy destinations are validated, aka Windows Shell Remote Code Execution Vulnerability.

Risk Information

Base Score
5.1
MODERATE
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C
EPSS Score
Exploitation Probability
29.278

Associated Vulnerability

VulnerabilityOS Platform
Internet Explorer Information Disclosure Vulnerability for Windows 8.1 for x86-based Systems (KB4088876)Windows
Internet Explorer Information Disclosure Vulnerability for Windows 8.1 for x64-based Systems (KB4088876)Windows
Internet Explorer Information Disclosure Vulnerability for Windows Server 2012 R2 for x64-based Systems (KB4088876)Windows
Internet Explorer Information Disclosure Vulnerability for Windows Server 2012 for x64-based Systems (KB4088877)Windows
Windows Shell Remote Code Execution Vulnerability for Windows 8.1 for x86-based Systems (KB4088879)Windows
Windows Shell Remote Code Execution Vulnerability for Windows 8.1 for x64-based Systems (KB4088879)Windows
Windows Shell Remote Code Execution Vulnerability for Windows Server 2012 R2 for x64-based Systems (KB4088879)Windows
Windows Shell Remote Code Execution Vulnerability for Windows Server 2012 for x64-based Systems (KB4088880)Windows
Internet Explorer Information Disclosure Vulnerability for Windows 10 Version 1507 for x64-based Systems (KB4088786) - CumulativeWindows
Internet Explorer Information Disclosure Vulnerability for Windows 10 Version 1511 for x86-based Systems (KB4088779) - CumulativeWindows
Internet Explorer Information Disclosure Vulnerability for Windows 10 Version 1511 for x64-based Systems (KB4088779) - CumulativeWindows
Internet Explorer Information Disclosure Vulnerability for Windows 10 Version 1607 for x86-based Systems (KB4088787) - CumulativeWindows
Internet Explorer Information Disclosure Vulnerability for Windows 10 Version 1607 for x64-based Systems (KB4088787) - CumulativeWindows
Internet Explorer Information Disclosure Vulnerability for Windows 10 Version 1607 for x86-based Systems (KB4088787) - DeltaWindows
Internet Explorer Information Disclosure Vulnerability for Windows 10 Version 1607 for x64-based Systems (KB4088787) - DeltaWindows
Internet Explorer Information Disclosure Vulnerability for Windows Server 2016 for x64-based Systems (KB4088787) - CumulativeWindows
Internet Explorer Information Disclosure Vulnerability for Windows Server 2016 for x64-based Systems (KB4088787) - DeltaWindows
Internet Explorer Information Disclosure Vulnerability for Windows 10 Version 1703 for x86-based Systems (KB4088782) - CumulativeWindows
Internet Explorer Information Disclosure Vulnerability for Windows 10 Version 1703 for x86-based Systems (KB4088782) - DeltaWindows
Internet Explorer Information Disclosure Vulnerability for Windows 10 Version 1703 for x64-based Systems (KB4088782) - DeltaWindows
Internet Explorer Information Disclosure Vulnerability for Windows 10 Version 1709 for x86-based Systems (KB4088776) - CumulativeWindows
Internet Explorer Information Disclosure Vulnerability for Windows 10 Version 1709 for x64-based Systems (KB4088776) - CumulativeWindows
Internet Explorer Information Disclosure Vulnerability for Windows 10 Version 1709 for x86-based Systems (KB4088776) - DeltaWindows
Internet Explorer Information Disclosure Vulnerability for Windows 10 Version 1709 for x64-based Systems (KB4088776) - DeltaWindows
Internet Explorer Information Disclosure Vulnerability for Windows 7 for x86-based Systems (KB4088875)Windows
Internet Explorer Information Disclosure Vulnerability for Windows 7 for x64-based Systems (KB4088875)Windows
Internet Explorer Information Disclosure Vulnerability for Windows Server 2008 R2 for x64-based Systems (KB4088875)Windows
Windows Shell Remote Code Execution Vulnerability for Windows 7 for x86-based Systems (KB4088878)Windows
Windows Shell Remote Code Execution Vulnerability for Windows 7 for x64-based Systems (KB4088878)Windows
Windows Shell Remote Code Execution Vulnerability for Windows Server 2008 R2 for x64-based Systems (KB4088878)Windows
Internet Explorer Information Disclosure Vulnerability for Windows 10 Version 1507 for x86-based Systems (KB4088786) - CumulativeWindows
Internet Explorer Information Disclosure Vulnerability for Windows 10 Version 1703 for x64-based Systems (KB4088782) - CumulativeWindows
Windows Shell Remote Code Execution Vulnerability for the windows shell remote code execution vulnerability in Windows Server 2008 for x86-based Systems (KB4089175)Windows
Windows Shell Remote Code Execution Vulnerability for the windows shell remote code execution vulnerability in Windows Server 2008 for x64-based Systems (KB4089175)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-240722018-03 Security Monthly Quality Rollup for Windows 8.1 for x86-based Systems (KB4088876)
PATCH-240732018-03 Security Monthly Quality Rollup for Windows 8.1 for x64-based Systems (KB4088876)
PATCH-240742018-03 Security Monthly Quality Rollup for Windows Server 2012 R2 for x64-based Systems (KB4088876)
PATCH-240752018-03 Security Monthly Quality Rollup for Windows Server 2012 for x64-based Systems (KB4088877)
PATCH-240792018-03 Security Only Quality Update for Windows 8.1 for x86-based Systems (KB4088879)
PATCH-240802018-03 Security Only Quality Update for Windows 8.1 for x64-based Systems (KB4088879)
PATCH-240812018-03 Security Only Quality Update for Windows Server 2012 R2 for x64-based Systems (KB4088879)
PATCH-240822018-03 Security Only Quality Update for Windows Server 2012 for x64-based Systems (KB4088880)
PATCH-240872018-03 Cumulative Update for Windows 10 Version 1507 for x64-based Systems (KB4088786)
PATCH-240882018-03 Cumulative Update for Windows 10 Version 1511 for x86-based Systems (KB4088779)
PATCH-240892018-03 Cumulative Update for Windows 10 Version 1511 for x64-based Systems (KB4088779)
PATCH-240902018-03 Cumulative Update for Windows 10 Version 1607 for x86-based Systems (KB4088787)
PATCH-240912018-03 Cumulative Update for Windows 10 Version 1607 for x64-based Systems (KB4088787)
PATCH-240922018-03 Delta Update for Windows 10 Version 1607 for x86-based Systems (KB4088787)
PATCH-240932018-03 Delta Update for Windows 10 Version 1607 for x64-based Systems (KB4088787)
PATCH-240942018-03 Cumulative Update for Windows Server 2016 for x64-based Systems (KB4088787)
PATCH-240952018-03 Delta Update for Windows Server 2016 for x64-based Systems (KB4088787)
PATCH-241002018-03 Cumulative Update for Windows 10 Version 1709 for x86-based Systems (KB4088776)
PATCH-241012018-03 Cumulative Update for Windows 10 Version 1709 for x64-based Systems (KB4088776)
PATCH-241022018-03 Delta Update for Windows 10 Version 1709 for x86-based Systems (KB4088776)
PATCH-241032018-03 Delta Update for Windows 10 Version 1709 for x64-based Systems (KB4088776)
PATCH-240692018-03 Security Monthly Quality Rollup for Windows 7 for x86-based Systems (KB4088875)
PATCH-240702018-03 Security Monthly Quality Rollup for Windows 7 for x64-based Systems (KB4088875)
PATCH-240712018-03 Security Monthly Quality Rollup for Windows Server 2008 R2 for x64-based Systems (KB4088875)
PATCH-240762018-03 Security Only Quality Update for Windows 7 for x86-based Systems (KB4088878)
PATCH-240772018-03 Security Only Quality Update for Windows 7 for x64-based Systems (KB4088878)
PATCH-240782018-03 Security Only Quality Update for Windows Server 2008 R2 for x64-based Systems (KB4088878)
PATCH-240862018-03 Cumulative Update for Windows 10 Version 1507 for x86-based Systems (KB4088786)
PATCH-241132018-03 Security Update for Windows Server 2008 for x86-based Systems (KB4089175)
PATCH-241142018-03 Security Update for Windows Server 2008 for x64-based Systems (KB4089175)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234