CVE-2018-8125 is a remote code execution vulnerability affecting Microsoft Edge, Windows 10, and Windows Server 2016, stemming from improper memory object access. This high-severity vulnerability (CVSS 7.5) can lead to complete compromise of confidentiality, integrity, and availability, requiring user interaction and high attack complexity. While it has a high EPSS score and FAUCET Risk Score, there is no evidence of active exploitation, nor are public exploit codes like Metasploit or ExploitDB available. Community discussion and media coverage indicate some awareness, primarily from its inclusion in a Microsoft Patch Tuesday update.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.