CVE-2018-8174 is a remote code execution vulnerability in the VBScript engine, affecting numerous Windows versions from Windows 7 to Windows 10 and various Server editions. This critical flaw allows attackers to execute arbitrary code due to how the engine handles objects in memory. With a CVSS score of 7.5 (HIGH) and an EPSS score of 0.94, it indicates a significant threat, requiring user interaction (e.g., visiting a malicious website) but leading to complete compromise of confidentiality, integrity, and availability. The vulnerability is actively exploited, as confirmed by its presence in the KEV catalog and association with ransomware campaigns. Exploit code is publicly available on ExploitDB, and it has garnered substantial community discussion and media coverage, highlighting its widespread impact and the urgency for patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1607:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1703:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1709:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1803:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.