{"api_version":"1","generated_at":"2026-07-23T07:34:01+00:00","cve":"CVE-2018-0743","urls":{"html":"https://cve.report/CVE-2018-0743","api":"https://cve.report/api/cve/CVE-2018-0743.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2018-0743","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2018-0743"},"summary":{"title":"CVE-2018-0743","description":"Windows Subsystem for Linux in Windows 10 version 1703, Windows 10 version 1709, and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way objects are handled in memory, aka \"Windows Subsystem for Linux Elevation of Privilege Vulnerability\".","state":"PUBLIC","assigner":"secure@microsoft.com","published_at":"2018-01-04 14:29:00","updated_at":"2019-10-03 00:03:00"},"problem_types":["NVD-CWE-noinfo"],"metrics":[],"references":[{"url":"https://twitter.com/AmarSaar/status/948892321755598848","name":"https://twitter.com/AmarSaar/status/948892321755598848","refsource":"MISC","tags":["Third Party Advisory"],"title":"Saar Amar na Twitterze: \"My new vuln CVE-2018-0743 in WSL was patched today && it's tweetable!\n\nint main(void) {\n    int n = 0xaaaaaaa;\n    void **p = calloc(n, 8);\n    for (; n; --n)\n        p[n-1] = \"\";\n    execv(\"\", p);\n}\n\nFull exploit at @bluehatil\nhttps://t.co/9DrHEZrsy9\"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.exploit-db.com/exploits/43962/","name":"43962","refsource":"EXPLOIT-DB","tags":["Exploit","Third Party Advisory","VDB Entry"],"title":"Microsoft Windows Subsystem for Linux - 'execve()' Local Privilege Escalation - Windows local Exploit","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/saaramar/execve_exploit","name":"https://github.com/saaramar/execve_exploit","refsource":"MISC","tags":["Exploit","Patch","Third Party Advisory"],"title":"GitHub - saaramar/execve_exploit: Hardcore corruption of my execve() vulnerability in WSL","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/102350","name":"102350","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"Malformed Request","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0743","name":"https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0743","refsource":"CONFIRM","tags":["Patch","Vendor Advisory"],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1040094","name":"1040094","refsource":"SECTRACK","tags":["Third Party Advisory","VDB Entry"],"title":"Windows Subsystem for Linux Integer Overflow Lets Local Users Gain Elevated Privileges - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2018-0743","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2018-0743","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2018","cve_id":"743","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_10","cpe6":"1703","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"743","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_10","cpe6":"1709","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"743","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_10","cpe6":"1703","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"743","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_10","cpe6":"1709","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"743","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_server_2016","cpe6":"1709","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"743","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_server_2016","cpe6":"1709","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"secure@microsoft.com","DATE_PUBLIC":"2018-01-03T00:00:00","ID":"CVE-2018-0743","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Windows Subsystem for Linux","version":{"version_data":[{"version_value":"Windows 10 version 1703, Windows 10 version1709, and Windows Server, version 1709"}]}}]},"vendor_name":"Microsoft Corporation"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Windows Subsystem for Linux in Windows 10 version 1703, Windows 10 version 1709, and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way objects are handled in memory, aka \"Windows Subsystem for Linux Elevation of Privilege Vulnerability\"."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Elevation of Privilege"}]}]},"references":{"reference_data":[{"name":"1040094","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1040094"},{"name":"https://github.com/saaramar/execve_exploit","refsource":"MISC","url":"https://github.com/saaramar/execve_exploit"},{"name":"https://twitter.com/AmarSaar/status/948892321755598848","refsource":"MISC","url":"https://twitter.com/AmarSaar/status/948892321755598848"},{"name":"43962","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/43962/"},{"name":"https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0743","refsource":"CONFIRM","url":"https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0743"},{"name":"102350","refsource":"BID","url":"http://www.securityfocus.com/bid/102350"}]}},"nvd":{"publishedDate":"2018-01-04 14:29:00","lastModifiedDate":"2019-10-03 00:03:00","problem_types":["NVD-CWE-noinfo"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7,"baseSeverity":"HIGH"},"exploitabilityScore":1,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:M/Au:N/C:P/I:P/A:P","accessVector":"LOCAL","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":4.4},"severity":"MEDIUM","exploitabilityScore":3.4,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:microsoft:windows_10:1703:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:microsoft:windows_10:1709:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:microsoft:windows_server_2016:1709:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2018","CveId":"743","Ordinal":"115683","Title":"CVE-2018-0743","CVE":"CVE-2018-0743","Year":"2018"},"notes":[{"CveYear":"2018","CveId":"743","Ordinal":"1","NoteData":"Windows Subsystem for Linux in Windows 10 version 1703, Windows 10 version 1709, and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way objects are handled in memory, aka \"Windows Subsystem for Linux Elevation of Privilege Vulnerability\".","Type":"Description","Title":null},{"CveYear":"2018","CveId":"743","Ordinal":"2","NoteData":"2018-01-04","Type":"Other","Title":"Published"},{"CveYear":"2018","CveId":"743","Ordinal":"3","NoteData":"2018-02-04","Type":"Other","Title":"Modified"}]}}}