CVE-2018-8140

MEDIUM

Description

An Elevation of Privilege vulnerability exists when Cortana retrieves data from user input services without consideration for status, aka "Cortana Elevation of Privilege Vulnerability." This affects Windows 10 Servers, Windows 10.

References

http://www.securityfocus.com/bid/104354

http://www.securitytracker.com/id/1041108

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8140

Details

Source: MITRE

Published: 2018-06-14

Updated: 2019-10-03

Risk Information

CVSS v2.0

Base Score: 4.6

Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 3.9

Severity: MEDIUM

CVSS v3.0

Base Score: 6.8

Vector: CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 0.9

Severity: MEDIUM