CVE-2018-0952 is an elevation-of-privilege vulnerability in the Windows Diagnostics Hub Standard Collector. The collector can create files in arbitrary locations. The issue involves symlink attacks against a privileged service performing file operations on behalf of a user, enabling a lower-privileged user to influence privileged file creation.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository is a Proof-of-Concept (PoC) exploit for CVE-2018-0952, a privilege escalation vulnerability in the Windows Diagnostics Hub Standard Collector Service. The exploit targets Windows 10, Windows Server (including 2016), and Visual Studio 2015/2017. The vulnerability arises from improper impersonation during file operations in the DiagnosticsHub.StandardCollector.Runtime.dll, allowing an attacker to copy a file to an arbitrary location (such as C:\Windows\System32) by abusing mount points and symlinks. The repository contains a Visual Studio solution with two main projects: a C# project (SystemCollector) that orchestrates the exploit logic and interacts with the vulnerable service, and a C++ DLL project (Payload) that serves as the payload (spawning notepad.exe as SYSTEM when loaded). The exploit demonstrates how a low-privileged user can achieve SYSTEM-level code execution by racing the service's file operations and planting a malicious DLL in a privileged directory. The code leverages the NtApiDotNet library for low-level file and handle manipulation. The README provides detailed technical background, exploitation steps, and references to advisories and write-ups.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.