The Credential Security Support Provider protocol (CredSSP) in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709 Windows Server 2016 and Windows Server, version 1709 allows a remote code execution vulnerability due to how CredSSP validates request during the authentication process, aka "CredSSP Remote Code Execution Vulnerability".
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-0886.json"
[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1511"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1607"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1703"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1709"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1803"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "r2-sp1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "r2-sp1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "r2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1709"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1803"
}
]
}
]