CVE-2018-8342 is an elevation of privilege vulnerability in the Network Driver Interface Specification (NDIS) of Windows 7 and Windows Server 2008 R2, where ndis.sys fails to properly validate buffer lengths. With a CVSS score of 7.8 (High), this vulnerability allows a local attacker with low privileges to achieve high confidentiality, integrity, and availability impacts without user interaction. There is no public exploit code available, nor is it listed in the CISA KEV catalog, indicating it is not actively exploited. Despite this, it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:* | ||
r2CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.