Executive brief
A remote code execution vulnerability exists in the Windows Shell due to improper validation of file paths. An attacker could exploit this to execute arbitrary code on a target system, typically requiring user interaction such as opening a specially crafted file.
Affected products
- Microsoft Windows 10 1703, 1709, 1803
- Microsoft Windows Server 1709, 1803
Timeline
- 2018-10-12: disclosed: Initial analysis by NIST
- 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-03-25: exploited: Reported as exploited in the wild in CISA KEV catalog