Executive brief
A remote code execution vulnerability exists in the Microsoft VBScript engine due to the way it handles objects in memory. An attacker could exploit this out-of-bounds write vulnerability to execute arbitrary code in the context of the current user, typically via a specially crafted website or document.
Affected products
- Microsoft Windows 7 Service Pack 1
- Microsoft Windows 8.1
- Microsoft Windows RT 8.1
- Microsoft Windows 10 1607, 1703, 1709, 1803
- Microsoft Windows Server 2008 Service Pack 2, R2 Service Pack 1
- Microsoft Windows Server 2012 R2
- Microsoft Windows Server 2016 1709, 1803
Timeline
- 2018-05-08: patched: Microsoft released security updates and advisory.
- 2022-02-15: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
- 2022-02-15: disclosed: NVD publication date.