CVE-2018-8414

HIGH(8.8)KEVLikely Exploited

Microsoft Windows Shell Remote Code Execution Vulnerability

Description

CVE-2018-8414 is a remote code execution vulnerability in the Microsoft Windows Shell that can be exploited through specially crafted SettingContent-ms files. An attacker can create a malicious SettingContent-ms file that, when opened by a user, executes arbitrary commands on the system. This file type was designed for Windows 10 settings shortcuts but can be abused to run PowerShell commands or other executables. The vulnerability was added to the CISA Known Exploited Vulnerabilities catalog on March 25, 2022, and with an EPSS score of 97.3% (99.9th percentile), exploitation is near-certain.

KEV Information

Vendor
Microsoft
Product
Windows
Date Added
March 25, 2022
Due Date
April 15, 2022
Required Action
Apply updates per vendor instructions.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.9

CWEs

Affected Products

VendorProductVersion
microsoftwindows 10 1703-
microsoftwindows 10 1709-
microsoftwindows 10 1803-
microsoftwindows server 1709-
microsoftwindows server 1803-

Multiple CVSS Assessments

Source: [email protected](Primary)
8.8
HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
8.8
HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

References

Weakness Type

CWE-94: Improper Control of Generation of Code (Code Injection)

CVE-2018-8414 is classified under CWE-94, which describes vulnerabilities involving improper control of code generation or execution. The Windows Shell does not properly validate the commands embedded in SettingContent-ms files, allowing an attacker to include arbitrary executable paths and command-line arguments that are executed when the file is opened.

Learn more: CWE-94 — Improper Control of Generation of Code

Impact Analysis

CVE-2018-8414 enables attackers to execute arbitrary code on Windows 10 systems through malicious SettingContent-ms files. The SettingContent-ms file type is particularly dangerous because it can be embedded in Office documents, delivered via email, or hosted on websites, and it bypasses many security controls that block traditional executable file types. The DeepLink element in these files can specify arbitrary command lines including PowerShell scripts, enabling full code execution with the privileges of the current user. If the victim has administrative privileges, the attacker gains complete control of the system. The EPSS score of 97.3% confirms near-certain exploitation.

Exploit Maturity

CVE-2018-8414 has been confirmed as actively exploited in the wild by CISA. The attack technique was widely publicized and is well-documented, with multiple proof-of-concept demonstrations showing how SettingContent-ms files can be embedded in Office documents to bypass security controls. With an EPSS score of 97.3% (99.9th percentile), exploitation is near-certain. The simplicity of crafting malicious SettingContent-ms files — they are simple XML — makes this vulnerability accessible to a wide range of attackers.

Remediation

  1. Apply Microsoft security updates: Install the August 2018 cumulative security update from Microsoft that addresses CVE-2018-8414.
  2. Block SettingContent-ms files: Configure email gateways, content filters, and endpoint protection to block SettingContent-ms files from being delivered or executed.
  3. Implement Attack Surface Reduction rules: Enable Windows Defender Attack Surface Reduction (ASR) rules that block Office applications from creating child processes and executing content from SettingContent-ms files.
  4. Restrict macro execution: Configure Office applications to block macros and embedded content from untrusted sources.
  5. Educate users: Train users to be cautious about opening unexpected file types, particularly those received via email or downloaded from the internet.

Technical Details

CVE-2018-8414 exploits the SettingContent-ms file type introduced in Windows 10. SettingContent-ms files are XML-based files designed to provide shortcuts to Windows Settings pages, containing a DeepLink element that specifies the settings page to open. The vulnerability exists because the Windows Shell does not restrict the DeepLink element to settings URIs — an attacker can specify arbitrary command lines, including paths to executables and PowerShell scripts with full command-line arguments. When a user opens the malicious SettingContent-ms file, Windows executes the embedded command without adequate security warnings. These files can also be embedded within Microsoft Office documents, bypassing security controls like Protected View that normally restrict execution of downloaded content.

Frequently Asked Questions

Is CVE-2018-8414 being actively exploited?

Yes. CISA has confirmed active exploitation of CVE-2018-8414. The attack technique is well-publicized and easily reproducible, making it a common vector for targeted attacks and phishing campaigns.

What products are affected by CVE-2018-8414?

CVE-2018-8414 affects Microsoft Windows 10 systems. The SettingContent-ms file type is specific to Windows 10 and is not present in earlier Windows versions.

How do I fix CVE-2018-8414?

Apply the August 2018 cumulative security update from Microsoft. Additionally, block SettingContent-ms files at email gateways and endpoint protection, and enable Attack Surface Reduction rules to prevent Office applications from launching child processes.

How severe is CVE-2018-8414?

CVE-2018-8414 is a critical remote code execution vulnerability with an EPSS score of 97.3%. The ability to embed malicious SettingContent-ms files in Office documents while bypassing security controls makes this a particularly effective attack vector.

CVSS Score

8.8
HIGH(8.8)

EPSS Score

EPSS Score73.97%
EPSS Percentile99.4%

Dates

PublishedAugust 15, 2018
Last ModifiedJune 17, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.