CVE-2018-8592HighCVSS 6.4

Windows Elevation Of Privilege Vulnerability

Published
November 13, 2018
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

An elevation of privilege vulnerability exists in Windows 10 version 1809 when installed from physical media (USB, DVD, etc.) with the “keep nothing” option selected during installation. Successful exploitation of the vulnerability could allow an attacker to gain local access to an affected system. To exploit the vulnerability, an attacker would need physical access to the console of the affected system. The update addresses the vulnerability by changing built-in account behavior after the setup process completes. For recommendations on managing the local administrator accounts, please see Implementing Least-Privilege Administrative Models

🎯 Affected products5

  • Windows 10 Version 1809 for 32-bit Systems
  • Windows 10 Version 1809 for ARM64-based Systems
  • Windows 10 Version 1809 for x64-based Systems
  • Windows Server 2019
  • Windows Server 2019 (Server Core installation)

✅ Remediation

KB4467708 (Security Update)

🔗 References (2)