CVE Database
/

CVE-2018-8256

Back to search

CVE-2018-8256

Published: Nov 14, 2018

Modified: Aug 5, 2024

PUBLISHED

Description

A remote code execution vulnerability exists when PowerShell improperly handles specially crafted files, aka "Microsoft PowerShell Remote Code Execution Vulnerability." This affects Windows RT 8.1, PowerShell Core 6.0, Microsoft.PowerShell.Archive 1.2.2.0, Windows Server 2016, Windows Server 2012, Windows Server 2008 R2, Windows Server 2019, Windows 7, Windows Server 2012 R2, PowerShell Core 6.1, Windows 10 Servers, Windows 10, Windows 8.1.

VendorProductVersions

Microsoft

Windows 7

affected
32-bit Systems Service Pack 1
affected
x64-based Systems Service Pack 1

Microsoft

Microsoft.PowerShell.Archive

affected
1.2.2.0

Microsoft

Windows 10 Servers

affected
version 1709 (Server Core Installation)
affected
version 1803 (Server Core Installation)

Microsoft

Windows Server 2012 R2

affected
(Server Core installation)

Microsoft

Windows RT 8.1

affected
Windows RT 8.1

Microsoft

Windows Server 2008 R2

affected
Itanium-Based Systems Service Pack 1
affected
x64-based Systems Service Pack 1
affected
x64-based Systems Service Pack 1 (Server Core installation)

Microsoft

Windows Server 2012

affected
(Server Core installation)

Microsoft

PowerShell Core

affected
6.0
affected
6.1

Microsoft

Windows Server 2016

affected
(Server Core installation)

Microsoft

Windows 8.1

affected
32-bit systems
affected
x64-based systems

Microsoft

Windows 10

affected
32-bit Systems
affected
Version 1607 for 32-bit Systems
affected
Version 1607 for x64-based Systems
affected
Version 1703 for 32-bit Systems
affected
Version 1703 for x64-based Systems

+10 more versions

Microsoft

Windows Server 2019

affected
(Server Core installation)

References

1042108
vdb-entry
x_refsource_SECTRACK
105781
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now