AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2018-1276

MEDIUM · CVSS 6.5 EPSS 1.04%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2018-05-17 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 6.5. It affects Windows. It may be remotely exploitable.

CVE
CVE-2018-1276
Severity
MEDIUM
CVSS
6.5
EPSS
1.04%
Windows

Original NVD Description

Windows 2012R2 stemcells, versions prior to 1200.17, contain an information exposure vulnerability on vSphere. A remote user with the ability to push apps can execute crafted commands to read the IaaS metadata from the VM, which may contain BOSH credentials.

Related CVEs

Other vulnerabilities affecting the same vendor(s)