peter bassill · operator
$ cve CVE-2018-8626 JSON

CVE-2018-8626

9.8
CRITICAL · CVSS 3.0 · EPSS 21.2% (pctl 98)

Patch early

EPSS 21.2% — above the 10% action threshold.

Description

A remote code execution vulnerability exists in Windows Domain Name System (DNS) servers when they fail to properly handle requests, aka "Windows DNS Server Heap Overflow Vulnerability." This affects Windows Server 2012 R2, Windows Server 2019, Windows Server 2016, Windows 10, Windows 10 Servers.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS21.24% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-787
On CISA KEVno
Public exploitnone known
Published2018-12-12
Last modified2026-06-17

Affected (4)

VendorProduct
microsoftwindows 10
microsoftwindows server 2012
microsoftwindows server 2016
microsoftwindows server 2019

References

→ the Explorer  ·  watch your stack  ·  NVD