CVE-2018-0824
CVE Published | 2018-05-09 |
---|---|
Related CWE(s) | CWE-502: Deserialization of Untrusted Data |
Related Vendor(s) | microsoft |
Related Product(s) | windows_10_1703, windows_7, windows_server_1803, windows_8.1, windows_server_1709, windows_server_2016, windows_10_1709, windows_10_1607, windows_10_1803, windows_10_1507, windows_server_2008, windows_rt_8.1, windows_server_2012 |
Exploitation Reported (CISA KEV) | 2024-08-05 |
CVSS 3 Base Score | 7.5 (HIGH) |
CVSS 3 Attack Complexity | HIGH |
CVSS 3 Attack Vector | NETWORK |
A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized objects, aka "Microsoft COM for Windows Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
Cyber Threat Graph Context
Explore how this CVE relates to the wider threat graph
Threat Reports Related to CVE-2018-0824
Report
APT41 likely compromised Taiwanese government-affiliated research institute with ShadowPad and Cobalt Strike
This blog post by researchers at Cisco Talos outlines a malicious campaign which they identified targeting a government affiliated research ...