ZeroHour

CVE-2018-0824

KEV PoC mass

Deserialization of Untrusted Data RCE in Microsoft COM for Windows

CISA: Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability

CVSS 3.1
8.8 high
EPSS
73%p99
Published
()
KEV added
AI analysis

CVE-2018-0824 is a deserialization of untrusted data flaw (CWE-502) in Microsoft COM for Windows: the COM subsystem fails to properly handle serialized objects, allowing a remote attacker to achieve remote code execution (CVSS 3.1: 8.8, network vector). It is triggered when the affected Windows system deserializes attacker-controlled serialized data; the CVSS vector indicates user interaction is required in typical attack scenarios. Successful exploitation yields code execution with the privileges of the user or service that handles the serialized object, compromising confidentiality, integrity, and availability on the host. The affected footprint is extremely broad, spanning Windows 7, 8.1 and RT 8.1, Windows 10 (versions 1507 through 1803), and Windows Server 2008 through 2016, including Server versions 1709 and 1803. The flaw is confirmed exploited in the wild — CISA added it to the Known Exploited Vulnerabilities catalog on 2024-08-05 — and a public PoC exists (Exploit-DB 44906), with EPSS estimating a ~73.2% probability of exploitation within 30 days.

What to do: Apply Microsoft's COM security updates to every in-scope Windows build, prioritizing internet-facing hosts and legacy systems (Windows 7, Windows Server 2008/2008 R2, Windows Server 2012) that commonly remain unpatched; because the flaw is on CISA's KEV list, patching is required for federal agencies under BOD 22-01. Verify patch installation via inventory rather than OS build alone, and where patching is impossible (end-of-support systems), isolate or restrict those hosts' network exposure. Ransomware use is not yet confirmed by CISA, but the high EPSS score and KEV listing warrant urgent remediation.

Affected
Microsoft Windows 101507, 1607, 1703, 1709, 1803
Microsoft Windows 7all editions listed by CISA (32-bit and x64)
Microsoft Windows 8.1all editions listed by CISA
Microsoft Windows RT 8.1all listed versions
Microsoft Windows Server 2008including 2008 R2 (per vulnerability description)
Microsoft Windows Server 2012including 2012 R2 (per vulnerability description)
Microsoft Windows Server 2016all listed versions
Microsoft Windows Server, version 1709all listed versions
Microsoft Windows Server, version 1803all listed versions
Estimated exposure
masshundreds of millions of Windows devices run the affected versions (Windows 7–10 and Server 2008–2016); residual unpatched exposure plausibly in the millions — The affected Windows client and server releases historically constituted the overwhelming majority of Microsoft's install base — on the order of hundreds of millions to over a billion devices — so residual exposure is dominated by…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized objects, aka "Microsoft COM for Windows Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1703, windows 10 1709, windows 10 1803, windows 7, windows 8.1, windows rt 8.1, windows server 1709, windows server 1803, windows server 2008, windows server 2012
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news