CVE-2018-0824

CVE Published 2018-05-09
Related CWE(s) CWE-502: Deserialization of Untrusted Data
Related Vendor(s) microsoft
Related Product(s) windows_10_1703, windows_7, windows_server_1803, windows_8.1, windows_server_1709, windows_server_2016, windows_10_1709, windows_10_1607, windows_10_1803, windows_10_1507, windows_server_2008, windows_rt_8.1, windows_server_2012
Exploitation Reported (CISA KEV) 2024-08-05
CVSS 3 Base Score 7.5 (HIGH)
CVSS 3 Attack Complexity HIGH
CVSS 3 Attack Vector NETWORK

A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized objects, aka "Microsoft COM for Windows Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Threat Reports Related to CVE-2018-0824

Report

APT41 likely compromised Taiwanese government-affiliated research institute with ShadowPad and Cobalt Strike

This blog post by researchers at Cisco Talos outlines a malicious campaign which they identified targeting a government affiliated research ...

Associated CAPEC Patterns

References