Vulnerability record · CVE-2018-0886 · published 14 March 2018
CVE-2018-0886: Microsoft Windows CredSSP improper authentication remote code execution
Microsoft · Windows 10
CredSSP in multiple Microsoft Windows versions fails to properly validate requests during authentication, allowing remote code execution. The flaw is tracked as CWE-287 improper authentication and affects Windows 7 through Windows 10 and corresponding Server releases. It matters because CredSSP is used for remote credential delegation, so a successful attack can compromise a host during the authentication handshake.
Description
The Credential Security Support Provider protocol (CredSSP) in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709 Windows Server 2016 and Windows Server, version 1709 allows a remote code execution vulnerability due to how CredSSP validates request during the authentication process, aka "CredSSP Remote Code Execution Vulnerability".
CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityPublic exploit code exists and EPSS is very high, but the CVSS vector requires local access, high complexity and user interaction, reducing mass exploitation risk.
What it is
CredSSP in multiple Microsoft Windows versions fails to properly validate requests during authentication, allowing remote code execution. The flaw is tracked as CWE-287 improper authentication and affects Windows 7 through Windows 10 and corresponding Server releases. It matters because CredSSP is used for remote credential delegation, so a successful attack can compromise a host during the authentication handshake.
Impact
An attacker can execute arbitrary code on the target system with the privileges of the affected process. Given the CVSS impact ratings of high confidentiality, integrity and availability, full compromise of the host is possible.
Attack surface
The CVSS vector is AV:L/AC:H/PR:N/UI:R, so the attack is local, requires high complexity and user interaction, and no privileges. The description frames it as remote code execution during CredSSP authentication, so the practical reach is through a crafted authentication request that a user must trigger.
Exploitation
CISA KEV does not list this CVE, but EPSS is 0.8197 (99.6th percentile) and multiple references are tagged Exploit, including Preempt advisories and Exploit-DB 44453, indicating public exploit code exists.
What to do
- Apply the Microsoft security update referenced in the vendor advisory for all affected Windows versions.
- Enforce CredSSP patching on both client and server sides, since the fix requires updated CredSSP behavior on both ends.
- Restrict or disable CredSSP/Remote Credential Guard where it is not operationally required.
- Limit remote desktop and WinRM exposure to trusted networks and require strong authentication.
- Monitor for and block known exploit traffic against CredSSP endpoints.
Detection
- Monitor Windows event logs for anomalous CredSSP authentication failures or unexpected credential delegation attempts.
- Inspect network traffic for CredSSP negotiation anomalies or known exploit signatures.
- Track unpatched Windows hosts that still expose RDP or WinRM with CredSSP enabled.
- Correlate process creation on RDP/WinRM hosts with unusual child processes following authentication.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2018-0886 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-0886), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.