Junglewise Threat Intelligence

CVE-2018-8174: Microsoft Windows VBScript Engine Out-of-Bounds Write Vulnerability

CVE-2018-8174 · Severity: critical · CVSS 7.5 · Exploited in the wild · Published 2022-02-15

Technologies: Microsoft Windows Server 2016, Microsoft Windows 7, Microsoft Windows, Microsoft Windows 8.1, Microsoft Windows Server 2008, Microsoft Windows Server 2012, Microsoft Windows 10, Microsoft Windows Rt 8.1. Vendors: Microsoft.

Executive brief

A remote code execution vulnerability exists in the Microsoft VBScript engine due to the way it handles objects in memory. An attacker could exploit this out-of-bounds write vulnerability to execute arbitrary code in the context of the current user, typically via a specially crafted website or document.

Affected products

  • Microsoft Windows 7 Service Pack 1
  • Microsoft Windows 8.1
  • Microsoft Windows RT 8.1
  • Microsoft Windows 10 1607, 1703, 1709, 1803
  • Microsoft Windows Server 2008 Service Pack 2, R2 Service Pack 1
  • Microsoft Windows Server 2012 R2
  • Microsoft Windows Server 2016 1709, 1803

Timeline

  • 2018-05-08: patched: Microsoft released security updates and advisory.
  • 2022-02-15: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2022-02-15: disclosed: NVD publication date.

Related threats