CVE-2018-0743PoC(microsoft / windows_10)

MEDIUMCVSS 7.0 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch microsoft windows_10 systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Windows Subsystem for Linux in Windows 10 version 1703, Windows 10 version 1709, and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way objects are handled in memory, aka "Windows Subsystem for Linux Elevation of Privilege Vulnerability".

4.0/ 10 priority

Sources & remediation

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10
  • windows_server_2016

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
windows_10windows_server_2016

2 versions affected across 2 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-06-16: 1PoC Mentioned / Linked · 2026-06-16: 1Exploit Tool / Code · 2026-06-16: 1Patch / Workaround · 2026-06-16: 1Technical Details · 2026-06-16: 106-16
Signal classification1 categories
PoC
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • OS Dev@OSdev_
    PoC

    One of the most interesting privilege escalation bugs in the Windows Subsystem for Linux (WSL) is CVE-2018-0743 - https://github.com/saaramar/execve_exploit The vulnerability stemmed from improper handling of objects in memory within WSL. By exploiting this flaw, a local authenticated attacker could manipulate the way Windows managed these objects, allowing them to elevate their privileges beyond their intended level. The resulting access could ultimately grant the attacker full administrative (SYSTEM-level) privileges, enabling complete control over the affected machine. Microsoft addressed the issue as part of its January 2018 security updates, eliminating the underlying memory handling flaw and preventing attackers from leveraging it for privilege escalation.

    Post summary

    A proof‑of‑concept exploit for CVE‑2018‑0743 is publicly available on GitHub, detailing a privilege‑escalation flaw in WSL that Microsoft later patched in January 2018.

    011047283.7K
    4.8K followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_101703--
OSmicrosoftwindows_101709--
OSmicrosoftwindows_server_20161709--

Explore more