CVE-2018-8115: Microsoft Windows Host Compute Service Shim

High severity, CVSS 8.6. EPSS: 34.6% chance of exploitation in the next 30 days.

A remote code execution vulnerability exists when the Windows Host Compute Service Shim (hcsshim) library fails to properly validate input while importing a container image, aka "Windows Host Compute Service Shim Remote Code Execution Vulnerability." This affects Windows Host Compute.

Affected products

  • Microsoft Windows Host Compute Service Shim: before 0.6.10 (fixed in 0.6.10)

Published 2018-05-02. Last modified 2026-06-17.