CVE-2018-0742 is a Windows Kernel Elevation of Privilege vulnerability affecting numerous versions of Windows 7, 8.1, 10, and Server editions, stemming from improper handling of objects in memory. This vulnerability carries a CVSSv3 score of 7.8 (High), indicating that a local attacker with low privileges can achieve high confidentiality, integrity, and availability impacts without user interaction. While no public exploit code (Metasploit, Nuclei, ExploitDB) is currently available and it is not listed in CISA's KEV catalog, its presence was noted in a BleepingComputer article regarding Microsoft's February Patch Tuesday. Community discussion and media coverage for this CVE are minimal, suggesting limited public attention despite its severity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:* | ||
1511CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:* | ||
1607CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:* | ||
1703CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1703:*:*:*:*:*:*:* | ||
1709CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1709:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.