CVE-2018-8454 is an information disclosure vulnerability in the Windows Audio Service, affecting Windows 10, Windows Server 2016, and Windows Server 2019, where improper memory handling can lead to sensitive data exposure. With a CVSS score of 5.5 (Medium), it requires local access and low privileges, but successful exploitation could result in a complete compromise of confidentiality. There is no known public exploit code (Metasploit, Nuclei, ExploitDB), and it is not listed in the CISA KEV catalog, indicating a low likelihood of active exploitation. Community discussion and media coverage are minimal, suggesting limited public awareness or interest.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1709CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1709:*:*:*:*:*:*:* | ||
1803CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1803:*:*:*:*:*:*:* | ||
1809CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1809:*:*:*:*:*:*:* | ||
1709CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2016:1709:*:*:*:*:*:*:* | ||
1803CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2016:1803:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.