Junglewise Threat Intelligence

CVE-2018-0824: Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability

CVE-2018-0824 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2024-08-05

Technologies: Microsoft Windows Server 2008, Microsoft Windows Server 2016, Microsoft Windows, Microsoft Windows 10, Microsoft Windows 8.1, Microsoft Windows 7, Microsoft Windows Server 2012, Microsoft Windows Rt 8.1. Vendors: Microsoft.

Executive brief

Microsoft COM for Windows fails to properly handle serialized objects, leading to a deserialization of untrusted data vulnerability. An attacker can exploit this to achieve remote code execution or privilege escalation via a specially crafted file or script.

Affected products

  • Microsoft Windows 10 1507, 1607, 1703, 1709, 1803
  • Microsoft Windows 7 SP1
  • Microsoft Windows 8.1
  • Microsoft Windows RT 8.1
  • Microsoft Windows Server 2008 SP2, R2 SP1
  • Microsoft Windows Server 2012 R2
  • Microsoft Windows Server 2016 1709, 1803

Timeline

  • 2018-06-12: patched: Vendor advisory and patch released by Microsoft.
  • 2018-06-18: other: Exploit published on Exploit-DB.
  • 2024-08-05: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2024-08-05: disclosed

Related threats