CVE-2018-0886

Description

The Credential Security Support Provider protocol (CredSSP) in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709 Windows Server 2016 and Windows Server, version 1709 allows a remote code execution vulnerability due to how CredSSP validates request during the authentication process, aka CredSSP Remote Code Execution Vulnerability.

Risk Information

Base Score
7.1
MODERATE
Vector
CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
EPSS Score
Exploitation Probability
91.354

Associated Vulnerability

VulnerabilityOS Platform
Internet Explorer Information Disclosure Vulnerability for Windows 8.1 for x86-based Systems (KB4088876)Windows
Internet Explorer Information Disclosure Vulnerability for Windows 8.1 for x64-based Systems (KB4088876)Windows
Internet Explorer Information Disclosure Vulnerability for Windows Server 2012 R2 for x64-based Systems (KB4088876)Windows
Internet Explorer Information Disclosure Vulnerability for Windows Server 2012 for x64-based Systems (KB4088877)Windows
Windows Shell Remote Code Execution Vulnerability for Windows 8.1 for x86-based Systems (KB4088879)Windows
Windows Shell Remote Code Execution Vulnerability for Windows 8.1 for x64-based Systems (KB4088879)Windows
Windows Shell Remote Code Execution Vulnerability for Windows Server 2012 R2 for x64-based Systems (KB4088879)Windows
Windows Shell Remote Code Execution Vulnerability for Windows Server 2012 for x64-based Systems (KB4088880)Windows
Internet Explorer Information Disclosure Vulnerability for Windows 10 Version 1511 for x86-based Systems (KB4088779) - CumulativeWindows
Internet Explorer Information Disclosure Vulnerability for Windows 10 Version 1511 for x64-based Systems (KB4088779) - CumulativeWindows
Internet Explorer Information Disclosure Vulnerability for Windows 10 Version 1607 for x86-based Systems (KB4088787) - CumulativeWindows
Internet Explorer Information Disclosure Vulnerability for Windows 10 Version 1607 for x64-based Systems (KB4088787) - CumulativeWindows
Internet Explorer Information Disclosure Vulnerability for Windows 10 Version 1607 for x86-based Systems (KB4088787) - DeltaWindows
Internet Explorer Information Disclosure Vulnerability for Windows 10 Version 1607 for x64-based Systems (KB4088787) - DeltaWindows
Internet Explorer Information Disclosure Vulnerability for Windows Server 2016 for x64-based Systems (KB4088787) - CumulativeWindows
Internet Explorer Information Disclosure Vulnerability for Windows Server 2016 for x64-based Systems (KB4088787) - DeltaWindows
Microsoft Browser Information Disclosure Vulnerability for Windows 10 Version 1607 for x64-based Systems (KB4103723) - CumulativeWindows
Microsoft Edge Information Disclosure Vulnerability for Windows 10 Version 1709 for x64-based Systems (KB4103727) - CumulativeWindows
Microsoft Edge Information Disclosure Vulnerability for Windows 10 Version 1709 for x64-based Systems (KB4103727) - DeltaWindows
Microsoft Edge Information Disclosure Vulnerability for Windows 10 Version 1709 for x86-based Systems (KB4103727) - CumulativeWindows
Microsoft Edge Information Disclosure Vulnerability for Windows 10 Version 1709 for x86-based Systems (KB4103727) - DeltaWindows
Microsoft Browser Information Disclosure Vulnerability for Windows Server 2016 (1803) for x64-based Systems (KB4103721) - CumulativeWindows
Microsoft Browser Information Disclosure Vulnerability for Windows 10 Version 1803 for x64-based Systems (KB4103721) - CumulativeWindows
Microsoft Browser Information Disclosure Vulnerability for Windows 10 Version 1703 for x64-based Systems (KB4103731) - CumulativeWindows
Microsoft Browser Information Disclosure Vulnerability for Windows 10 Version 1703 for x64-based Systems (KB4103731) - DeltaWindows
Microsoft Browser Information Disclosure Vulnerability for Windows 10 Version 1703 for x86-based Systems (KB4103731) - CumulativeWindows
Microsoft Browser Information Disclosure Vulnerability for Windows 10 Version 1703 for x86-based Systems (KB4103731) - DeltaWindows
Microsoft Browser Information Disclosure Vulnerability for Windows Server 2016 for x64-based Systems (KB4103723) - CumulativeWindows
Microsoft Browser Information Disclosure Vulnerability for Windows 10 Version 1607 for x64-based Systems (KB4103723) - DeltaWindows
Microsoft Browser Information Disclosure Vulnerability for Windows Server 2016 for x64-based Systems (KB4103723) - DeltaWindows
Microsoft Browser Information Disclosure Vulnerability for Windows 10 Version 1607 for x86-based Systems (KB4103723) - CumulativeWindows
Microsoft Browser Information Disclosure Vulnerability for Windows 10 Version 1607 for x86-based Systems (KB4103723) - DeltaWindows
Microsoft Browser Information Disclosure Vulnerability for Windows 10 Version 1507 for x64-based Systems (KB4103716) - CumulativeWindows
Microsoft Browser Information Disclosure Vulnerability for Windows Server 2008 R2 for x64-based Systems (KB4103718)Windows
Microsoft Browser Information Disclosure Vulnerability for Windows 7 for x64-based Systems (KB4103718)Windows
Microsoft Browser Information Disclosure Vulnerability for Windows 7 for x86-based Systems (KB4103718)Windows
Microsoft Browser Information Disclosure Vulnerability for Windows Server 2012 R2 for x64-based Systems (KB4103725)Windows
Microsoft Browser Information Disclosure Vulnerability for Windows 8.1 for x64-based Systems (KB4103725)Windows
Microsoft Browser Information Disclosure Vulnerability for Windows 8.1 for x86-based Systems (KB4103725)Windows
Microsoft Windows Information Disclosure Vulnerability for Windows Server 2012 for x64-based Systems (KB4103730)Windows
Microsoft Windows Information Disclosure Vulnerability for Windows Server 2008 R2 for x64-based Systems (KB4103712)Windows
Microsoft Windows Information Disclosure Vulnerability for Windows 7 for x64-based Systems (KB4103712)Windows
Microsoft Windows Information Disclosure Vulnerability for Windows 7 for x86-based Systems (KB4103712)Windows
Microsoft Windows Information Disclosure Vulnerability for Windows Server 2012 R2 for x64-based Systems (KB4103715)Windows
Microsoft Windows Information Disclosure Vulnerability for Windows 8.1 for x64-based Systems (KB4103715)Windows
Microsoft Windows Information Disclosure Vulnerability for Windows 8.1 for x86-based Systems (KB4103715)Windows
Microsoft Windows Information Disclosure Vulnerability for Windows Server 2012 for x64-based Systems (KB4103726)Windows
Microsoft Edge Information Disclosure Vulnerability for Windows Server 2016 (1709) for x64-based Systems (KB4103727) - CumulativeWindows
Microsoft Edge Information Disclosure Vulnerability for Windows Server 2016 (1709) for x64-based Systems (KB4103727) - DeltaWindows
Microsoft Browser Information Disclosure Vulnerability for Windows 10 Version 1507 for x86-based Systems (KB4103716) - CumulativeWindows
Microsoft Browser Information Disclosure Vulnerability for Windows 10 Version 1803 for x86-based Systems (KB4103721) - CumulativeWindows
CredSSP Remote Code Execution Vulnerability for the credssp remote code execution vulnerability in Windows Server 2008 for x86-based Systems (KB4056564)Windows
CredSSP Remote Code Execution Vulnerability for the credssp remote code execution vulnerability in Windows Server 2008 for x64-based Systems (KB4056564)Windows
SUSE-SU-2019:0134-1(SUSE Linux Enterprise Desktop 12-SP3 ) freerdp-2.0.0~git.1463131968.4e66df7-12.8.1.x86_64.rpmLinux
SUSE-SU-2019:0134-1(SUSE Linux Enterprise Desktop 12-SP4 ) freerdp-debuginfo-2.0.0~git.1463131968.4e66df7-12.8.1.x86_64.rpmLinux
SUSE-SU-2019:0134-1(SUSE Linux Enterprise Desktop 12-SP4 ) freerdp-debugsource-2.0.0~git.1463131968.4e66df7-12.8.1.x86_64.rpmLinux
SUSE-SU-2019:0134-1(SUSE Linux Enterprise Desktop 12-SP4 ) libfreerdp2-2.0.0~git.1463131968.4e66df7-12.8.1.x86_64.rpmLinux
SUSE-SU-2019:0134-1(SUSE Linux Enterprise Desktop 12-SP4 ) libfreerdp2-debuginfo-2.0.0~git.1463131968.4e66df7-12.8.1.x86_64.rpmLinux

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-240722018-03 Security Monthly Quality Rollup for Windows 8.1 for x86-based Systems (KB4088876)
PATCH-240732018-03 Security Monthly Quality Rollup for Windows 8.1 for x64-based Systems (KB4088876)
PATCH-240742018-03 Security Monthly Quality Rollup for Windows Server 2012 R2 for x64-based Systems (KB4088876)
PATCH-240752018-03 Security Monthly Quality Rollup for Windows Server 2012 for x64-based Systems (KB4088877)
PATCH-240792018-03 Security Only Quality Update for Windows 8.1 for x86-based Systems (KB4088879)
PATCH-240802018-03 Security Only Quality Update for Windows 8.1 for x64-based Systems (KB4088879)
PATCH-240812018-03 Security Only Quality Update for Windows Server 2012 R2 for x64-based Systems (KB4088879)
PATCH-240822018-03 Security Only Quality Update for Windows Server 2012 for x64-based Systems (KB4088880)
PATCH-240882018-03 Cumulative Update for Windows 10 Version 1511 for x86-based Systems (KB4088779)
PATCH-240892018-03 Cumulative Update for Windows 10 Version 1511 for x64-based Systems (KB4088779)
PATCH-240902018-03 Cumulative Update for Windows 10 Version 1607 for x86-based Systems (KB4088787)
PATCH-240912018-03 Cumulative Update for Windows 10 Version 1607 for x64-based Systems (KB4088787)
PATCH-240922018-03 Delta Update for Windows 10 Version 1607 for x86-based Systems (KB4088787)
PATCH-240932018-03 Delta Update for Windows 10 Version 1607 for x64-based Systems (KB4088787)
PATCH-240942018-03 Cumulative Update for Windows Server 2016 for x64-based Systems (KB4088787)
PATCH-240952018-03 Delta Update for Windows Server 2016 for x64-based Systems (KB4088787)
PATCH-244222018-05 Cumulative Update for Windows 10 Version 1607 for x64-based Systems (KB4103723)
PATCH-244322018-05 Cumulative Update for Windows 10 Version 1709 for x64-based Systems (KB4103727)
PATCH-244312018-05 Delta Update for Windows 10 Version 1709 for x64-based Systems (KB4103727)
PATCH-244302018-05 Cumulative Update for Windows 10 Version 1709 for x86-based Systems (KB4103727)
PATCH-244292018-05 Delta Update for Windows 10 Version 1709 for x86-based Systems (KB4103727)
PATCH-244342018-05 Cumulative Update for Windows Server 2016 (1803) for x64-based Systems (KB4103721)
PATCH-244332018-05 Cumulative Update for Windows 10 Version 1803 for x64-based Systems (KB4103721)
PATCH-244172018-05 Cumulative Update for Windows Server 2016 for x64-based Systems (KB4103723)
PATCH-244212018-05 Delta Update for Windows 10 Version 1607 for x64-based Systems (KB4103723)
PATCH-244182018-05 Delta Update for Windows Server 2016 for x64-based Systems (KB4103723)
PATCH-244202018-05 Cumulative Update for Windows 10 Version 1607 for x86-based Systems (KB4103723)
PATCH-244192018-05 Delta Update for Windows 10 Version 1607 for x86-based Systems (KB4103723)
PATCH-244232018-05 Cumulative Update for Windows 10 Version 1507 for x64-based Systems (KB4103716)
PATCH-244632018-05 Security Monthly Quality Rollup for Windows Server 2008 R2 for x64-based Systems (KB4103718)
PATCH-244622018-05 Security Monthly Quality Rollup for Windows 7 for x64-based Systems (KB4103718)
PATCH-244612018-05 Security Monthly Quality Rollup for Windows 7 for x86-based Systems (KB4103718)
PATCH-244662018-05 Security Monthly Quality Rollup for Windows Server 2012 R2 for x64-based Systems (KB4103725)
PATCH-244642018-05 Security Monthly Quality Rollup for Windows 8.1 for x64-based Systems (KB4103725)
PATCH-244652018-05 Security Monthly Quality Rollup for Windows 8.1 for x86-based Systems (KB4103725)
PATCH-244672018-05 Security Monthly Quality Rollup for Windows Server 2012 for x64-based Systems (KB4103730)
PATCH-244552018-05 Security Only Quality Update for Windows Server 2008 R2 for x64-based Systems (KB4103712)
PATCH-244562018-05 Security Only Quality Update for Windows 7 for x64-based Systems (KB4103712)
PATCH-244542018-05 Security Only Quality Update for Windows 7 for x86-based Systems (KB4103712)
PATCH-244592018-05 Security Only Quality Update for Windows Server 2012 R2 for x64-based Systems (KB4103715)
PATCH-244582018-05 Security Only Quality Update for Windows 8.1 for x64-based Systems (KB4103715)
PATCH-244572018-05 Security Only Quality Update for Windows 8.1 for x86-based Systems (KB4103715)
PATCH-244602018-05 Security Only Quality Update for Windows Server 2012 for x64-based Systems (KB4103726)
PATCH-246552018-05 Cumulative Update for Windows Server 2016 (1709) for x64-based Systems (KB4103727)
PATCH-246562018-05 Delta Update for Windows Server 2016 (1709) for x64-based Systems (KB4103727)
PATCH-244242018-05 Cumulative Update for Windows 10 Version 1507 for x86-based Systems (KB4103716)
PATCH-244352018-05 Cumulative Update for Windows 10 Version 1803 for x86-based Systems (KB4103721)
PATCH-241162018-03 Security Update for Windows Server 2008 for x86-based Systems (KB4056564)
PATCH-241172018-03 Security Update for Windows Server 2008 for x64-based Systems (KB4056564)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234