New Search

Windows Elevation Of Privilege Vulnerability - CVE-2018-8592

oval:org.cisecurity:def:5991

An elevation of privilege vulnerability exists in Windows 10 version 1809 when installed from physical media (USB DVD etc.) with the “keep nothing” option selected during installation. Successful exploitation of the vulnerability could allow an attacker to gain local access to an affected system. To exploit the vulnerability an attacker would need physical access to the console of the affected system. The update addresses the vulnerability by changing built-in account behavior after the setup process completes. For recommendations on managing the local administrator accounts please see Implementing Least-Privilege Administrative Models

Family:
windows
Status:
ACCEPTED
Platform(s):
  • Microsoft Windows 10
  • Microsoft Windows Server 2019
Class:
vulnerability
Reference(s):
  • CVE-2018-8592
  • MSRC-CVE-2018-8592
  • KB4467708
Product(s):