CVE-2018-0743
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 2.8%
from disclosure to weapon29 days
Published on NVDJan 4
1st PoC+29d
exploitation probability
2.8%top 15% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
Windows Subsystem for Linux in Windows 10 version 1703, Windows 10 version 1709, and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way objects are handled in memory, aka "Windows Subsystem for Linux Elevation of Privilege Vulnerability".
Affected products
Microsoft Corporation · Windows Subsystem for Linuxpublic PoCs found — 2✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/43962cve_referencewww.exploit-db.com/exploits/43962/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
https://github.com/saaramar/execve_exploithttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0743https://twitter.com/AmarSaar/status/948892321755598848https://www.exploit-db.com/exploits/43962/http://www.securityfocus.com/bid/102350http://www.securitytracker.com/id/1040094