← Vulnerability feed

Vulnerability record · CVE-2018-8414 · published 15 August 2018

CVE-2018-8414: Windows Shell path validation flaw allows remote code execution

Microsoft · Windows 10 1703

The Windows Shell fails to properly validate file paths, which can lead to remote code execution. The flaw affects Windows 10 and Windows Server builds listed in the record, and Microsoft classifies it as a Windows Shell Remote Code Execution Vulnerability. Because the shell is a core user-facing component, successful exploitation can hand an attacker full control of the affected host.

8.8 CVSS 3.1 High CISA KEV since 25 Mar 2022 EPSS 74% · top 0.5% CWE-20 · Improper input validation
8.8CVSS 3.1 base score, v2 9.3
74%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
5Affected product versions listed by NVD
7References
17 Jun 2026Last modified by NVD

Description

A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths, aka "Windows Shell Remote Code Execution Vulnerability." This affects Windows 10 Servers, Windows 10.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityThe flaw is in CISA's Known Exploited Vulnerabilities catalog with a very high EPSS score and allows remote code execution, so it warrants immediate patching.

What it is

The Windows Shell fails to properly validate file paths, which can lead to remote code execution. The flaw affects Windows 10 and Windows Server builds listed in the record, and Microsoft classifies it as a Windows Shell Remote Code Execution Vulnerability. Because the shell is a core user-facing component, successful exploitation can hand an attacker full control of the affected host.

Impact

An attacker who exploits the flaw can execute arbitrary code with the privileges of the affected user, giving high impact to confidentiality, integrity and availability. In practice this means code execution on the victim's machine rather than just information disclosure.

Attack surface

The CVSS vector is network-reachable with no privileges required, but user interaction is required, so the victim must open or interact with a crafted file or path. No authentication is needed on the attacker's side.

Exploitation

The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog, indicating exploitation in the wild, and EPSS gives it a 30-day probability of about 0.74 (99.5th percentile). The reference tags include a vendor patch advisory and a US Government resource, but no public exploit code is described in the record.

What to do

  • Apply the Microsoft security update referenced in the vendor advisory for CVE-2018-8414 as the first action.
  • Confirm all affected Windows 10 and Windows Server builds in the environment are patched, including 1703, 1709, 1803, Server 1709 and Server 1803.
  • Enforce the CISA KEV remediation deadline and track completion for internet-facing and user workstation fleets.
  • Reduce exposure by restricting execution of untrusted files and tightening email and web download controls that deliver crafted paths to the shell.

Detection

  • Monitor for suspicious child processes spawned by explorer.exe or other shell components, especially script interpreters and command shells.
  • Alert on file or path names containing unusual characters or traversal sequences being opened by shell-related processes.
  • Review endpoint telemetry for code execution originating from user-opened documents or archives on affected Windows builds.
  • Correlate process creation events with known exploitation patterns and the CISA KEV listing to prioritize triage.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2018-8414 to the Known Exploited Vulnerabilities catalog on 25 March 2022 as "Microsoft Windows Shell Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 15 April 2022.

Affected products

5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-8414 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2017-8543Windows Search memory handling flaw allows remote code executionWindows Search fails to properly handle objects in memory, allowing an unauthenticated remote attacker to execute code on affected Windows systems. T…KEVEPSS 74%analysed8.8CVE-2020-1020Windows Adobe Type Manager Library font parsing out-of-bounds write RCEMicrosoft Windows Adobe Type Manager Library mishandles a specially crafted multi-master font in Adobe Type 1 PostScript format, causing an out-of-bo…KEVEPSS 65%analysed8.8CVE-2019-0903Windows GDI memory handling remote code executionWindows Graphics Device Interface (GDI) mishandles objects in memory, allowing remote code execution. The record gives no root-cause detail beyond th…KEVEPSS 22%analysed8.8CVE-2018-0824Microsoft COM for Windows deserialization remote code executionMicrosoft COM for Windows fails to properly handle serialized objects, allowing untrusted data deserialization (CWE-502). A crafted serialized object…KEVEPSS 73%analysed8.8CVE-2017-8464Windows Shell .LNK icon parsing remote code executionWindows Shell fails to properly handle a crafted .LNK shortcut when its icon is parsed by Windows Explorer or any other application that reads shortc…KEVEPSS 90%analysed8.1CVE-2020-0601Windows CryptoAPI ECC certificate validation spoofing flawWindows CryptoAPI (Crypt32.dll) improperly validates Elliptic Curve Cryptography certificates, allowing a spoofed code-signing certificate to be trus…KEVEPSS 89%analysed7.8CVE-2021-28310Microsoft Windows Win32k out-of-bounds write privilege escalationCVE-2021-28310 is an out-of-bounds write (CWE-787) in the Windows Win32k component that allows a local user to elevate privileges. It affects multipl…KEVEPSS 8.3%analysed7.8CVE-2021-1732Microsoft Windows Win32k out-of-bounds write privilege escalationCVE-2021-1732 is an out-of-bounds write (CWE-787) in the Windows Win32k component that allows a local user to elevate privileges. It affects multiple…KEVEPSS 78%analysed

Source: NIST National Vulnerability Database (record CVE-2018-8414), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.