CVE-2018-0824
KEV PoC massDeserialization of Untrusted Data RCE in Microsoft COM for Windows
CISA: Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability
CVE-2018-0824 is a deserialization of untrusted data flaw (CWE-502) in Microsoft COM for Windows: the COM subsystem fails to properly handle serialized objects, allowing a remote attacker to achieve remote code execution (CVSS 3.1: 8.8, network vector). It is triggered when the affected Windows system deserializes attacker-controlled serialized data; the CVSS vector indicates user interaction is required in typical attack scenarios. Successful exploitation yields code execution with the privileges of the user or service that handles the serialized object, compromising confidentiality, integrity, and availability on the host. The affected footprint is extremely broad, spanning Windows 7, 8.1 and RT 8.1, Windows 10 (versions 1507 through 1803), and Windows Server 2008 through 2016, including Server versions 1709 and 1803. The flaw is confirmed exploited in the wild — CISA added it to the Known Exploited Vulnerabilities catalog on 2024-08-05 — and a public PoC exists (Exploit-DB 44906), with EPSS estimating a ~73.2% probability of exploitation within 30 days.
What to do: Apply Microsoft's COM security updates to every in-scope Windows build, prioritizing internet-facing hosts and legacy systems (Windows 7, Windows Server 2008/2008 R2, Windows Server 2012) that commonly remain unpatched; because the flaw is on CISA's KEV list, patching is required for federal agencies under BOD 22-01. Verify patch installation via inventory rather than OS build alone, and where patching is impossible (end-of-support systems), isolate or restrict those hosts' network exposure. Ransomware use is not yet confirmed by CISA, but the high EPSS score and KEV listing warrant urgent remediation.
| Microsoft Windows 10 | 1507, 1607, 1703, 1709, 1803 |
| Microsoft Windows 7 | all editions listed by CISA (32-bit and x64) |
| Microsoft Windows 8.1 | all editions listed by CISA |
| Microsoft Windows RT 8.1 | all listed versions |
| Microsoft Windows Server 2008 | including 2008 R2 (per vulnerability description) |
| Microsoft Windows Server 2012 | including 2012 R2 (per vulnerability description) |
| Microsoft Windows Server 2016 | all listed versions |
| Microsoft Windows Server, version 1709 | all listed versions |
| Microsoft Windows Server, version 1803 | all listed versions |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized objects, aka "Microsoft COM for Windows Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
- Affected
- Microsoft Windows
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1607, windows 10 1703, windows 10 1709, windows 10 1803, windows 7, windows 8.1, windows rt 8.1, windows server 1709, windows server 1803, windows server 2008, windows server 2012
- Weakness
- CWE-502
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H