CVE-2018-8136 is a remote code execution vulnerability in Windows that stems from how the operating system handles objects in memory. It impacts a wide range of Windows versions, including Windows 7, 8.1, 10, and various Windows Server editions. With a CVSS score of 7.8 (High), this vulnerability allows an unauthenticated attacker to achieve high confidentiality, integrity, and availability impact with low attack complexity, though user interaction is required. Despite its high severity and a FAUCET Risk Score of 93/100, there is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are minimal, with only one article mentioning it in the context of Microsoft's May 2018 Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:* | ||
1607CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:* | ||
1703CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1703:*:*:*:*:*:*:* | ||
1709CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1709:*:*:*:*:*:*:* | ||
1803CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1803:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.