Executive brief
Microsoft COM for Windows fails to properly handle serialized objects, leading to a deserialization of untrusted data vulnerability. An attacker can exploit this to achieve remote code execution or privilege escalation via a specially crafted file or script.
Affected products
- Microsoft Windows 10 1507, 1607, 1703, 1709, 1803
- Microsoft Windows 7 SP1
- Microsoft Windows 8.1
- Microsoft Windows RT 8.1
- Microsoft Windows Server 2008 SP2, R2 SP1
- Microsoft Windows Server 2012 R2
- Microsoft Windows Server 2016 1709, 1803
Timeline
- 2018-06-12: patched: Vendor advisory and patch released by Microsoft.
- 2018-06-18: other: Exploit published on Exploit-DB.
- 2024-08-05: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
- 2024-08-05: disclosed