CVE-2018-0878 is an information disclosure vulnerability in Microsoft Windows Remote Assistance, affecting various Windows client and server versions. It stems from improper processing of XML External Entities (XXE), allowing an attacker to potentially disclose sensitive information. While the CVSS score is low (3.1), indicating a low impact on confidentiality and requiring user interaction, its FAUCET Risk Score of 96/100 suggests a higher practical risk. Although not on the KEV list, exploit code is publicly available via ExploitDB, and there has been significant community discussion and media coverage, including reports of its potential use in targeted attacks.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:* | ||
1511CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:* | ||
1607CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:* | ||
1703CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1703:*:*:*:*:*:*:* | ||
1709CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1709:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.