CVE-2018-8172 is a remote code execution vulnerability in Microsoft Visual Studio and Expression Blend 4. The flaw allows an attacker to execute arbitrary code when the software fails to validate the source markup of an unbuilt project file. With a CVSS score of 7.8 (HIGH), this vulnerability has a low attack complexity and can lead to high impacts on confidentiality, integrity, and availability if a user is tricked into opening a malicious file. While there is no known active exploitation or public exploit code available (Metasploit, Nuclei, ExploitDB), it has garnered some community discussion and media coverage, indicating awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2CPE matchmatch criteria | cpe:2.3:a:microsoft:expression_blend:2:sp2:*:*:*:*:*:* | ||
3CPE matchmatch criteria | cpe:2.3:a:microsoft:expression_blend:3:sp1:*:*:*:*:*:* | ||
4CPE matchmatch criteria | cpe:2.3:a:microsoft:expression_blend:4:sp3:*:*:*:*:*:* | ||
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio:2010:sp1:*:*:*:*:*:* | ||
2012CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio:2012:update_5:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.