CVE-2018-8306 describes a command injection vulnerability in the Microsoft Wireless Display Adapter (MWDA) and its associated firmware, specifically affecting the V2 Software, due to improper management of user input. This medium-severity vulnerability has a CVSS score of 5.5, indicating an attack vector that requires adjacent network access and low privileges, with low impact on confidentiality, integrity, and availability. While there is no evidence of active exploitation, nor publicly available exploit code in Metasploit or ExploitDB, the vulnerability has received minimal community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0.8350CPE matchmatch criteria | cpe:2.3:o:microsoft:wireless_display_adapter_firmware:2.0.8350:*:*:*:*:*:*:* | ||
2.0.8365CPE matchmatch criteria | cpe:2.3:o:microsoft:wireless_display_adapter_firmware:2.0.8365:*:*:*:*:*:*:* | ||
2.0.8372CPE matchmatch criteria | cpe:2.3:o:microsoft:wireless_display_adapter_firmware:2.0.8372:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.