CVE-2018-0880 is an elevation of privilege vulnerability in the Desktop Bridge component of Windows 10 (versions 1607, 1703, 1709) and Windows Server (2016, version 1709), stemming from improper management of the virtual registry. This vulnerability has a CVSS score of 7.0 (HIGH), indicating that a local attacker with low privileges could achieve high impact on confidentiality, integrity, and availability, though with high attack complexity. While not listed in CISA's KEV catalog, public exploit code exists (EDB-44314) and it has garnered some community discussion and media coverage, suggesting awareness among researchers. Its high FAUCET Risk Score of 96/100 further emphasizes its potential danger.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:* | ||
1607CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:* | ||
1703CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1703:*:*:*:*:*:*:* | ||
1709CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1709:*:*:*:*:*:*:* | ||
1709CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server:1709:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.