CVE-2018-8126 is a security feature bypass vulnerability in Internet Explorer 11 that allows an attacker to bypass User Mode Code Integrity (UMCI) policies. This vulnerability affects Microsoft Internet Explorer, Windows 10, and Windows Server 2016. With a CVSS score of 8.8 (HIGH), it presents a significant risk, allowing for high impact to confidentiality, integrity, and availability through a low-complexity network attack requiring user interaction. There is no evidence of active exploitation, nor are public exploit modules available in Metasploit, Nuclei, or ExploitDB, though it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11CPE matchmatch criteria | cpe:2.3:a:microsoft:internet_explorer:11:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.