Microsoft Cortana CVE-2018-8253 Elevation of Privilege Vulnerability

description-logoDescription

An elevation of privilege vulnerability exists when Microsoft Cortana allows arbitrary website browsing on the lockscreen. An attacker who successfully exploited the vulnerability could steal browser stored passwords or log on to websites as another user. To exploit the vulnerability, an attacker would require physical access to the console and the system must have Microsoft Cortana assistance enabled. The security update addresses the vulnerability by preventing Microsoft Cortana from allowing arbitrary website browsing on the lockscreen.

affected-products-logoAffected Applications

Windows Server 2016
Windows 10

CVE References

CVE-2018-8253