CVE-2018-8274 is a remote code execution vulnerability in Microsoft Edge, specifically a memory corruption flaw, affecting Microsoft Edge and Windows 10. This vulnerability carries a high CVSS score of 7.5, indicating a network-based attack with high complexity, requiring user interaction, and potentially leading to complete compromise of confidentiality, integrity, and availability. While no public exploit code is currently available (Metasploit, Nuclei, ExploitDB), its high EPSS score and FAUCET Risk Score suggest a significant potential for exploitation. The vulnerability received limited community discussion and media coverage, primarily noted in Microsoft's July 2018 Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.