4.4
CVSSv2

CVE-2018-0821

Published: 15/02/2018 Updated: 03/10/2019
CVSS v2 Base Score: 4.4 | Impact Score: 6.4 | Exploitability Score: 3.4
CVSS v3 Base Score: 7 | Impact Score: 5.9 | Exploitability Score: 1
VMScore: 445
Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

AppContainer in Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way constrained impersonations are handled, aka "Windows AppContainer Elevation Of Privilege Vulnerability".

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft windows 10 1607

microsoft windows 10 -

microsoft windows server 2016 1709

microsoft windows server 2016 -

microsoft windows 10 1703

microsoft windows 10 1709

microsoft windows 10 1511

Exploits

Windows: Constrained Impersonation Capability EoP Platform: Windows 10 1703/1709 (not tested earlier versions) Class: Elevation of Privilege Summary: It’s possible to use the constrained impersonation capability added in Windows 10 to impersonate a lowbox SYSTEM token leading to EoP Description: Windows 10 added a new security check during im ...