CVE-2018-8446 is an information disclosure vulnerability in the Windows kernel affecting various versions of Windows 7, 8.1, 10, and Server editions. It arises from the kernel's improper handling of objects in memory, potentially allowing an authenticated local attacker to read sensitive data. Rated with a CVSS score of 5.5 (Medium), this vulnerability has a low attack complexity and requires local user privileges, but it can lead to a complete loss of confidentiality (C:H). There is no impact on integrity or availability. Currently, there is no public exploit code available in Metasploit, Nuclei, or ExploitDB, and it is not listed in CISA's KEV catalog. Community discussion and media coverage are minimal, suggesting limited active exploitation or widespread attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:* | ||
1607CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:* | ||
1703CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1703:*:*:*:*:*:*:* | ||
1709CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1709:*:*:*:*:*:*:* | ||
1803CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1803:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.