CVE-2018-0824 is a critical remote code execution vulnerability in Microsoft COM for Windows, affecting numerous Windows versions including Windows 7, 8.1, 10, and various Server editions. This vulnerability, stemming from improper handling of serialized objects, carries a CVSS score of 8.8 (HIGH) due to its network-based attack vector, low attack complexity, and potential for complete compromise of confidentiality, integrity, and availability. It is actively exploited in the wild, listed in CISA's KEV catalog, and has publicly available exploit code, including a Metasploit module and an ExploitDB entry for privilege escalation. The high EPSS score and significant community discussion further underscore its active exploitation and widespread concern.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1507:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1607:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1703:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1709:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1803:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.