ZeroHour

CVE-2018-8174

KEV ransomware PoC ×2mass1

Out-of-Bounds Write RCE in Microsoft Windows VBScript Engine

CISA: Microsoft Windows VBScript Engine Out-of-Bounds Write Vulnerability

CVSS 3.1
7.5 high
EPSS
88%p100
Published
()
KEV added
AI analysis

CVE-2018-8174 is an out-of-bounds write (CWE-787) in the Microsoft Windows VBScript engine, caused by the way it handles objects in memory. An attacker triggers it by convincing a user to visit a specially crafted website or open crafted content that invokes the VBScript engine (for example via Internet Explorer or a document preview), requiring user interaction. Successful exploitation yields remote code execution with the privileges of the logged-on user, enabling program installation, data theft and account takeover. All listed Windows client and server releases are affected: Windows 7, 8.1, RT 8.1, Windows 10 (1607-1803), and Windows Server 2008/2008 R2, 2012/2012 R2, 2016. Exploitation is in the wild: the flaw was fixed in the May 2018 Patch Tuesday, is listed in CISA KEV with known ransomware use, and public PoCs (0patch, ExploitDB 44741) and exploit kit usage have been documented; EPSS puts its 30-day exploitation probability at 88.5%.

What to do: Apply Microsoft's May 2018 security updates (and any later cumulative or Extended Security Updates) to every listed Windows client and server release, as required by the CISA KEV listing, prioritizing internet-reachable and user-facing systems given known ransomware use. Upgrade out-of-support platforms (Windows 7/8.1/RT 8.1, Server 2008/2008 R2, 2012/2012 R2) to supported builds or ensure ESU coverage. As interim mitigation, block VBScript execution in Internet Explorer web zones using Microsoft's documented Group Policy/registry settings, and hunt for prior exploitation on legacy systems.

Affected
microsoft windows 101607, 1703, 1709, 1803 (pre-May 2018 security updates)
microsoft windows 7all supported builds prior to the May 2018 security update
microsoft windows 8.1all supported builds prior to the May 2018 security update
microsoft windows rt 8.1all devices prior to the May 2018 security update
microsoft windows server 2008all supported editions, including 2008 R2 per CISA, prior to the May 2018 security update
microsoft windows server 2012all supported editions, including 2012 R2 per CISA, prior to the May 2018 security update
microsoft windows server 2016all supported editions (Windows 10 Servers) prior to the May 2018 security update
Estimated exposure
masshundreds of millions of Windows PCs and servers (affected desktop releases dominated the ~1B+ device Windows install base at disclosure) — Windows 7, 8.1 and Windows 10 1607-1803 together accounted for the overwhelming majority of active Windows devices in 2018, and the vulnerable VBScript engine ships by default with Internet Explorer on all listed client and server…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
microsoft
Products
windows 10 1607, windows 10 1703, windows 10 1709, windows 10 1803, windows 7, windows 8.1, windows rt 8.1, windows server 2008, windows server 2012, windows server 2016
Weakness
CWE-787
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news