Microsoft Cortana Elevation of Privilege Vulnerability - CVE-2018-8253
|ID: oval:org.secpod.oval:def:47139||Date: (C)2018-08-15 (M)2018-11-15|
|Class: VULNERABILITY||Family: windows|
An elevation of privilege vulnerability exists when Microsoft Cortana allows arbitrary website browsing on the lockscreen. An attacker who successfully exploited the vulnerability could steal browser stored passwords or log on to websites as another user. To exploit the vulnerability, an attacker would require physical access to the console and the system must have Microsoft Cortana assistance enabled. The security update addresses the vulnerability by preventing Microsoft Cortana from allowing arbitrary website browsing on the lockscreen.
|Microsoft Windows Server 2016|
|Microsoft Windows 10|