Vulnerability record · CVE-2018-8414 · published 15 August 2018
CVE-2018-8414: Windows Shell path validation flaw allows remote code execution
Microsoft · Windows 10 1703
The Windows Shell fails to properly validate file paths, which can lead to remote code execution. The flaw affects Windows 10 and Windows Server builds listed in the record, and Microsoft classifies it as a Windows Shell Remote Code Execution Vulnerability. Because the shell is a core user-facing component, successful exploitation can hand an attacker full control of the affected host.
Description
A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths, aka "Windows Shell Remote Code Execution Vulnerability." This affects Windows 10 Servers, Windows 10.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
critical priorityThe flaw is in CISA's Known Exploited Vulnerabilities catalog with a very high EPSS score and allows remote code execution, so it warrants immediate patching.
What it is
The Windows Shell fails to properly validate file paths, which can lead to remote code execution. The flaw affects Windows 10 and Windows Server builds listed in the record, and Microsoft classifies it as a Windows Shell Remote Code Execution Vulnerability. Because the shell is a core user-facing component, successful exploitation can hand an attacker full control of the affected host.
Impact
An attacker who exploits the flaw can execute arbitrary code with the privileges of the affected user, giving high impact to confidentiality, integrity and availability. In practice this means code execution on the victim's machine rather than just information disclosure.
Attack surface
The CVSS vector is network-reachable with no privileges required, but user interaction is required, so the victim must open or interact with a crafted file or path. No authentication is needed on the attacker's side.
Exploitation
The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog, indicating exploitation in the wild, and EPSS gives it a 30-day probability of about 0.74 (99.5th percentile). The reference tags include a vendor patch advisory and a US Government resource, but no public exploit code is described in the record.
What to do
- Apply the Microsoft security update referenced in the vendor advisory for CVE-2018-8414 as the first action.
- Confirm all affected Windows 10 and Windows Server builds in the environment are patched, including 1703, 1709, 1803, Server 1709 and Server 1803.
- Enforce the CISA KEV remediation deadline and track completion for internet-facing and user workstation fleets.
- Reduce exposure by restricting execution of untrusted files and tightening email and web download controls that deliver crafted paths to the shell.
Detection
- Monitor for suspicious child processes spawned by explorer.exe or other shell components, especially script interpreters and command shells.
- Alert on file or path names containing unusual characters or traversal sequences being opened by shell-related processes.
- Review endpoint telemetry for code execution originating from user-opened documents or archives on affected Windows builds.
- Correlate process creation events with known exploitation patterns and the CISA KEV listing to prioritize triage.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2018-8414 to the Known Exploited Vulnerabilities catalog on 25 March 2022 as "Microsoft Windows Shell Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 15 April 2022.
Affected products
5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/105016 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1041458 | Broken LinkThird Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8414 | PatchVendor Advisory |
| http://www.securityfocus.com/bid/105016 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1041458 | Broken LinkThird Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8414 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-8414 | US Government Resource |
Track CVE-2018-8414 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-8414), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.