CVE-2018-8140

EUVD-2018-19812
An Elevation of Privilege vulnerability exists when Cortana retrieves data from user input services without consideration for status, aka "Cortana Elevation of Privilege Vulnerability." This affects Windows 10 Servers, Windows 10.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.8 MEDIUM
PHYSICAL
LOW
NONE
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 82%
Affected Products (NVD)
VendorProductVersion
microsoftwindows_server_1803
-
𝑥
= Vulnerable software versions
Windows Releases
Platform
Version
Windows 10
1709 (x64, x86)
1803 (x64, x86)
Windows Server
1709 Server Core
1803 Server Core