High severity7.8NVD Advisory· Published Dec 12, 2018· Updated Jun 17, 2026
CVE-2018-8599
CVE-2018-8599
Description
An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly impersonates certain file operations, aka "Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability." This affects Microsoft Visual Studio, Windows Server 2019, Windows Server 2016, Windows 10, Windows 10 Servers.
Affected products
20cpe:2.3:a:microsoft:visual_studio:2015:update3:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:microsoft:visual_studio:2015:update3:*:*:*:*:*:*
- (no CPE)
- (no CPE)range: 2015 Update 3
- cpe:2.3:a:microsoft:visual_studio_2017:15.9:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_10:1703:*:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_10:1709:*:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_10:1803:*:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_10:1809:*:*:*:*:*:*:*
- (no CPE)range: 32-bit Systems
cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_server_2016:1709:*:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_server_2016:1803:*:*:*:*:*:*:*
- (no CPE)range: (Server Core installation)
cpe:2.3:o:microsoft:windows_server_2019:-:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:microsoft:windows_server_2019:-:*:*:*:*:*:*:*
- (no CPE)range: (Server Core installation)
- Range: version 1709 (Server Core Installation)
Patches
Vulnerability mechanics
References
2- portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8599nvdPatchVendor Advisory
- www.securityfocus.com/bid/106094nvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.