CVE-2018-8306
Summary
| CVE | CVE-2018-8306 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-07-11 00:29:00 UTC |
| Updated | 2019-10-03 00:03:00 UTC |
| Description | A command injection vulnerability exists in the Microsoft Wireless Display Adapter (MWDA) when the Microsoft Wireless Display Adapter does not properly manage user input, aka "Microsoft Wireless Display Adapter Command Injection Vulnerability." This affects Microsoft Wireless Display Adapter V2 Software. |
Risk And Classification
Problem Types: CWE-77
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Microsoft | Wireless Display Adapter | 2 | All | All | All |
| Hardware | Microsoft | Wireless Display Adapter | 2 | All | All | All |
| Operating System | Microsoft | Wireless Display Adapter Firmware | 2.0.8350 | All | All | All |
| Operating System | Microsoft | Wireless Display Adapter Firmware | 2.0.8365 | All | All | All |
| Operating System | Microsoft | Wireless Display Adapter Firmware | 2.0.8372 | All | All | All |
| Operating System | Microsoft | Wireless Display Adapter Firmware | 2.0.8350 | All | All | All |
| Operating System | Microsoft | Wireless Display Adapter Firmware | 2.0.8365 | All | All | All |
| Operating System | Microsoft | Wireless Display Adapter Firmware | 2.0.8372 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Microsoft Wireless Display Adapter Flaw in Processing Administartive Input Lets Remote Authenticated Users Deny Service - SecurityTracker | SECTRACK | www.securitytracker.com | Third Party Advisory, VDB Entry |
| Microsoft Wireless Display Adapter CVE-2018-8306 Command Injection Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8306 | CONFIRM | portal.msrc.microsoft.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.