CVE-2018-8342: Microsoft Windows 7

High severity, CVSS 7.8. EPSS: 1.2% chance of exploitation in the next 30 days.

An elevation of privilege vulnerability exists in the Network Driver Interface Specification (NDIS) when ndis.sys fails to check the length of a buffer prior to copying memory to it, aka "Windows NDIS Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2008 R2. This CVE ID is unique from CVE-2018-8343.

Affected products

  • Microsoft Windows 7: affected versions not specified
  • Microsoft Windows Server 2008: version r2 only

Published 2018-08-15. Last modified 2026-06-17.