CVE-2018-0833 is a denial-of-service vulnerability affecting the SMBv2/SMBv3 client in Microsoft Windows 8.1, RT 8.1, and Server 2012 R2, caused by improper handling of specially crafted requests. With a CVSS score of 5.3 (Medium), it has a high availability impact (A:H) and requires low privileges (PR:L) and high attack complexity (AC:H) over the network (AV:N). While not listed in CISA's KEV catalog, public exploit code exists on ExploitDB, and the vulnerability has garnered significant community discussion and media coverage, indicating its relevance.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:* | ||
r2CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.