Microsoft Windows Shell Remote Code Execution Vulnerability Exploit (CVE-2018-8414)

Microsoft Windows Shell does not properly validate file paths, allowing the execution of ".SettingContent-ms" files from outside the "ImmersiveControlPanel" folder. This module runs a malicious web site on the CORE IMPACT Console and waits for an unsuspecting user to trigger the exploit by connecting to the web site.
Exploit Platform
Exploit Type
Product Name