VDB

GCVE-110-CERTCC-2018-228297

GCVE-110-CERTCC-2018-228297
Advisory PublishedCVSS 4.6/10
Vulnetix · Advisory published December 19, 2018
The Microsoft Windows MsiAdvertiseProduct function contains a race-condition vulnerability, which can allow an authentication attacker to elevate privileges to read protected files.

Risk Scores

CVSS 2.0
4.6/10
Medium · AV:L/AC:L/Au:S/C:C/I:N/A:N
certcc-cam
certcc-cam
impact0population0exploitation0widely_known0score_current0ease_of_exploitation0
certcc-vrda
certcc-vrda
d1_impact2d1_population4d1_direct_report1
certcc-cvss-temporal-env
certcc-cvss-temporal-env
temporal_score4.4remediation_levelUreport_confidenceCenvironmental_score4.3333685472target_distributionHenvironmental_vectorCDP:ND/TD:H/CR:ND/IR:ND/AR:ND

Browse GCVE Records

74,198 records in the GCVE database · Updated July 21, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›