CVE-2018-0823 is an elevation of privilege vulnerability affecting Windows 10 version 1709 and Windows Server, version 1709, stemming from how the Named Pipe File System (NPFS) handles objects. This vulnerability carries a high CVSS score of 7.0, indicating a local attack vector with high impact on confidentiality, integrity, and availability, though with high attack complexity. While not listed on CISA's KEV catalog, public exploit code exists on ExploitDB, and it has received some community discussion and media coverage, suggesting awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1709CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1709:*:*:*:*:*:*:* | ||
1709CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2016:1709:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.