Remote code execution in Microsoft Windows VBScript Engine

Published: 2018-04-10 22:53:25
Severity High
Patch available YES
Number of vulnerabilities 1
CVE ID CVE-2018-1004
Exploitation vector Network
Public exploit N/A
Vulnerable software Windows
Windows Server
Microsoft Internet Explorer
Vulnerable software versions Windows 8.1
Windows 7
Windows 10
Windows RT 8.1
Windows Server 2012
Windows Server 2012 R2
Windows Server 2008 R2
Windows Server 2016
Microsoft Internet Explorer 9
Vendor URL Microsoft

Security Advisory

1) Buffer overflow


The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to boundary error when processing HTML content within VBScript engine. A remote unauthenticated attacker can create a specially crafted webpage, trick the victim into opening it with Internet Explorer, trigger buffer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Install updates from vendor's website.

External links

Back to List