CVE-2018-8337 is a security feature bypass vulnerability in the Windows Subsystem for Linux (WSL) that arises from improper handling of case sensitivity, affecting Windows 10 and Windows Server 2016. Rated Medium (CVSS 5.3), a local attacker could exploit this with low complexity to achieve limited confidentiality, integrity, and availability impacts. There is no evidence of active exploitation, and public exploit code (Metasploit, Nuclei, ExploitDB) is unavailable. Despite limited community discussion, it received media coverage during Microsoft's September 2018 Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1709CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1709:*:*:*:*:*:*:* | ||
1709CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2016:1709:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.