Vulnerability Name: CVE-2018-8482 (CCN-150387) Assigned: 2018-10-09 Published: 2018-10-09 Updated: 2020-08-24 Summary: An information disclosure vulnerability exists when Windows Media Player improperly discloses file information, aka "Windows Media Player Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8481 . CVSS v3 Severity: 3.1 Low  (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N  )2.7 Low  (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C  )Exploitability Metrics: Attack Vector (AV):  NetworkAttack Complexity (AC):  HighPrivileges Required (PR):  NoneUser Interaction (UI):  RequiredScope: Scope (S):  UnchangedImpact Metrics: Confidentiality (C):  LowIntegrity (I):  NoneAvailibility (A):  None
3.5 Low  (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N  )3.1 Low  (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C  )Exploitability Metrics: Attack Vector (AV):  NetworkAttack Complexity (AC):  LowPrivileges Required (PR):  LowUser Interaction (UI):  RequiredScope: Scope (S):  UnchangedImpact Metrics: Confidentiality (C):  LowIntegrity (I):  NoneAvailibility (A):  None
CVSS v2 Severity: 2.6 Low  (CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N  )Exploitability Metrics: Access Vector (AV):  NetworkAccess Complexity (AC):  HighAuthentication (Au):  NoneImpact Metrics: Confidentiality (C):  PartialIntegrity (I):  NoneAvailibility (A):  None
4.0 Medium  (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N  )Exploitability Metrics: Access Vector (AV):  NetworkAccess Complexity (AC):  LowAthentication (Au):  Single_InstanceImpact Metrics: Confidentiality (C):  PartialIntegrity (I):  NoneAvailibility (A):  None
Vulnerability Type: CWE-noinfo Vulnerability Consequences: Obtain Information References: Source: MITRE Type: CNACVE-2018-8482  Source: BID Type: Third Party Advisory, VDB Entry105469  Source: CCN Type: BID-105469Microsoft Windows Media Player CVE-2018-8482 Information Disclosure Vulnerability  Source: SECTRACK Type: Third Party Advisory, VDB Entry1041829  Source: XF Type: UNKNOWNms-media-cve20188482-info-disc(150387)  Source: CCN Type: Microsoft Security TechCenter - October 2018Windows Windows Media Player Information Disclosure Vulnerability  Source: CONFIRM Type: Patch, Vendor Advisoryhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8482  Vulnerable Configuration: Configuration 1 :cpe:/o:microsoft:windows_10:-:*:*:*:*:*:*:* OR cpe:/o:microsoft:windows_10:1607:*:*:*:*:*:*:*  OR cpe:/o:microsoft:windows_10:1703:*:*:*:*:*:*:*  OR cpe:/o:microsoft:windows_10:1709:*:*:*:*:*:*:*  OR cpe:/o:microsoft:windows_10:1803:*:*:*:*:*:*:*  OR cpe:/o:microsoft:windows_10:1809:*:*:*:*:*:*:*  OR cpe:/o:microsoft:windows_7:-:sp1:*:*:*:*:*:*  OR cpe:/o:microsoft:windows_8.1:*:*:*:*:*:*:*:*  OR cpe:/o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*  OR cpe:/o:microsoft:windows_server_2008:*:sp2:*:*:*:*:*:*  OR cpe:/o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:*  OR cpe:/o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*  OR cpe:/o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*  OR cpe:/o:microsoft:windows_server_2016:-:*:*:*:*:*:*:*  OR cpe:/o:microsoft:windows_server_1709:-:*:*:*:*:*:x64:*  OR cpe:/o:microsoft:windows_server_1803:-:*:*:*:*:*:x64:*  OR cpe:/o:microsoft:windows_server_2019:-:*:*:*:*:*:*:*  Configuration CCN 1 :cpe:/o:microsoft:windows_server_2008:*:sp2:*:*:*:*:x32:* OR cpe:/o:microsoft:windows_server_2008:*:sp2:*:*:*:*:x64:*  OR cpe:/o:microsoft:windows_server_2008:*:sp2:*:*:*:*:itanium:*  OR cpe:/o:microsoft:windows_7:-:sp1:-:*:-:-:x32:*  OR cpe:/o:microsoft:windows_7:*:sp1:*:*:*:*:x64:*  OR cpe:/o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*  OR cpe:/o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:itanium:*  OR cpe:/o:microsoft:windows_server_2012:*:*:*:*:*:*:*:*  OR cpe:/o:microsoft:windows_8.1:-:-:-:*:-:-:x32:*  OR cpe:/o:microsoft:windows_8.1:*:*:*:*:*:*:x64:*  OR cpe:/o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*  OR cpe:/o:microsoft:windows_rt_8.1:*:*:*:*:*:*:*:*  OR cpe:/o:microsoft:windows_10:-:*:*:*:*:*:x32:*  OR cpe:/o:microsoft:windows_10:*:*:*:*:*:*:x64:*  OR cpe:/o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*  OR cpe:/o:microsoft:windows_server:1709:*:*:*:*:*:*:*  OR cpe:/o:microsoft:windows_server:1803:*:*:*:*:*:*:*  OR cpe:/o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*    Denotes that component is vulnerable   BACK   
  microsoft  windows 10 -    
microsoft  windows 10 1607    
microsoft  windows 10 1703    
microsoft  windows 10 1709    
microsoft  windows 10 1803    
microsoft  windows 10 1809    
microsoft  windows 7 - sp1    
microsoft  windows 8.1 *    
microsoft  windows rt 8.1 -    
microsoft  windows server 2008 - sp2    
microsoft  windows server 2008 r2 sp1    
microsoft  windows server 2012 -    
microsoft  windows server 2012 r2    
microsoft  windows server 2016 -    
microsoft  windows server 2016 1709    
microsoft  windows server 2016 1803    
microsoft  windows server 2019 -    
microsoft  windows server 2008 sp2    
microsoft  windows server 2008 sp2    
microsoft  windows server 2008 
microsoft  windows 7 - sp1    
microsoft  windows 7 * sp1    
microsoft  windows server 2008 r2    
microsoft  windows server 2008 r2    
microsoft  windows server 2012 
microsoft  windows 8.1 - -    
microsoft  windows 8.1 * 
microsoft  windows server 2012 r2    
microsoft  windows rt 8.1 * 
microsoft  windows 10 - 
microsoft  windows 10 * 
microsoft  windows server 2016 
microsoft  windows server 1709 
microsoft  windows server 1803 
microsoft  windows server 2019