An elevation of privilege vulnerability exists in the Network Driver Interface Specification (NDIS) when ndis.sys fails to check the length of a buffer prior to copying memory to it, aka "Windows NDIS Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8342.

Project Subscriptions

Vendors Products
Microsoft Subscribe
Windows 10 Subscribe
Windows 7 Subscribe
Windows 8.1 Subscribe
Windows Rt 8.1 Subscribe
Windows Server 2008 Subscribe
Windows Server 2012 Subscribe
Windows Server 2016 Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2018-19994 An elevation of privilege vulnerability exists in the Network Driver Interface Specification (NDIS) when ndis.sys fails to check the length of a buffer prior to copying memory to it, aka "Windows NDIS Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8342.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00254}

epss

{'score': 0.00244}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2024-08-05T06:54:35.412Z

Reserved: 2018-03-14T00:00:00

Link: CVE-2018-8343

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-08-15T17:29:04.313

Modified: 2024-11-21T04:13:39.137

Link: CVE-2018-8343

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses