Windows SMB Server
CVE-2018-8444 — Windows SMB Information Disclosure Vulnerability
Executive Summary
An information disclosure vulnerability exists in the way that the Microsoft Server Message Block 2.0 (SMBv2) server handles certain requests. An attacker who successfully exploited this vulnerability could craft a special packet, which could lead to information disclosure from the server. To exploit the vulnerability, in most situations, an unauthenticated attacker could send a specially crafted packet to a targeted SMBv2 server. The security update addresses the vulnerability by correcting how SMBv2 handles these specially crafted requests.
Overview
7
CVSS HIGH
Important
MS Severity
Not Exploited
MS Exploit Status
N/A
MS Exploit Likelihood
CVSS Vector
ATTACK VECTOR
Network
ATTACK COMPLEXITY
High
PRIVILEGES REQUIRED
None
USER INTERACTION
None
SCOPE
Unchanged
CONFIDENTIALITY
High
INTEGRITY
Low
AVAILABILITY
Low
EXPLOIT CODE MATURITY
Proof-of-Concept
REMEDIATION LEVEL
Official Fix
REPORT CONFIDENCE
Confirmed
Temporal Score: 6.3
EPSS Score
0.05859
probability of exploitation in the next 30 days
0.92531 percentile - updated 2026-08-14
View on FIRST.org
Affected Products
3 affected products
| Product | KB Article | Severity | Impact | Restart Required |
|---|---|---|---|---|
| Windows 10 for 32-bit Systems | 4457132 (Security Update) |
Important | Information Disclosure | Yes |
| Windows 10 for x64-based Systems | 4457132 (Security Update) |
Important | Information Disclosure | Yes |
| Windows 8.1 for 32-bit systems 4457129 (Monthly Rollup) 4457143 (Security Only) Important Information Disclosure 4343898 Base: 7.0 Temporal: 6.3 Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L/E:P/RL:O/RC:C Yes None Windows 8.1 for x64-based systems 4457129 (Monthly Rollup) 4457143 (Security Only) Important Information Disclosure 4343898 Base: 7.0 Temporal: 6.3 Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L/E:P/RL:O/RC:C Yes None Windows RT 8.1 | 4457129 (Monthly Rollup) |
Important | Information Disclosure | Yes |
Patches
2 patches
| Article | Type | Restart |
|---|---|---|
4457132 |
Security Update | Yes |
4457129 |
Monthly Rollup | Yes |
Exploits & PoC
No public exploit or PoC has been linked for this CVE yet. When available, references are sourced from public repositories and may be unverified or non-functional — review carefully before use.
Detection Rules
No public Sigma or Nuclei detection rule has been mapped to this CVE yet. Coverage is concentrated on exploited / high-profile vulnerabilities; check SigmaHQ for updates.
Acknowledgments
Haikuo Xie of Baidu Security Lab
References
On This Page