CVE-2018-8441 is an elevation of privilege vulnerability stemming from an integer overflow within the Windows Subsystem for Linux (WSL), affecting Windows 10 and Windows Server 2016. With a CVSS score of 7.8 (HIGH), it allows a local attacker to gain elevated privileges with low attack complexity and no user interaction, potentially leading to high impact on confidentiality, integrity, and availability. There is no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed in the CISA KEV catalog, indicating no active exploitation. Community discussion and media coverage are minimal, suggesting limited public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1803CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1803:*:*:*:*:*:*:* | ||
1803CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2016:1803:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.