CVE-2018-8346 is a remote code execution vulnerability in Microsoft Windows, specifically affecting Windows 7, Windows Server 2008, and Windows Server 2008 R2. This flaw allows an attacker to execute arbitrary code if a specially crafted .LNK file is processed. With a CVSS score of 8.8 (High), it presents a significant risk due to its network-based attack vector and high impact on confidentiality, integrity, and availability, though user interaction is required. While no public exploit code is readily available (Metasploit, Nuclei, ExploitDB), it has garnered some community discussion and media coverage, indicating awareness, but it is not currently listed as actively exploited or on the CISA KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:* | ||
r2CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.