Memory corruption in Microsoft products - CVE-2018-8174
Published: April 21, 2018 / Updated: August 2, 2022
Vulnerability identifier: #VU12077
CSH Severity: Critical
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-8174
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability:
The vulnerability is being exploited in the wild
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error within the VBScript engine. A remote attacker can trick the victim into visiting a specially crafted website or open a malicious Office file and execute arbitrary code on the target system.
Note: the vulnerability is being actively exploited in the wild against victims in Asia region. The vulnerability is dubbed "double play".
The vulnerability exists due to a boundary error within the VBScript engine. A remote attacker can trick the victim into visiting a specially crafted website or open a malicious Office file and execute arbitrary code on the target system.
Note: the vulnerability is being actively exploited in the wild against victims in Asia region. The vulnerability is dubbed "double play".
Affected software
Microsoft Windows
Windows Server
Windows Live Messenger
Windows Server
Windows Live Messenger
How to mitigate CVE-2018-8174
Install updates from vendor's website.
Links to Public Exploits and PoC-codes
- Exploit #8207 - rtfkit (generate RTF exploit payload. uses cve-2017-11882, cve-2017-8570, cve-2018-0802, and cve-2018-8174.) (August 2, 2022)
- Exploit #4841 - rtfkit (generate RTF exploit payload. uses cve-2017-11882, cve-2017-8570, cve-2018-0802, and cve-2018-8174.) (November 17, 2020)
- Exploit #4751 - Foxit Reader SDK ActiveX Launch Action New Window Command Injection Remote Code Execution Vulnerability (October 27, 2020)
- Exploit #2251 - cve-2018-8174_analysis (Analysis of VBS exploit CVE-2018-8174) (April 1, 2020)
- Exploit #1947 - CVE-2018-8174-msf (CVE-2018-8174 - VBScript memory corruption exploit.) (March 18, 2020)
- Exploit #1955 - Rig-Exploit-for-CVE-2018-8174 (Rig Exploit for CVE-2018-8174 As with its previous campaigns, Rig’s Seamless campaign uses malvertising. In this case, the malvertisements have a hidden iframe that redirects victims to Rig’s landing page, which includes a (March 18, 2020)
- Exploit #2163 - ie11_vbscript_exploit (Exploit Generator for CVE-2018-8174 & CVE-2019-0768 (RCE via VBScript Execution in IE11)) (March 18, 2020)
External References
- https://twitter.com/360CoreSec/status/987229032994361345
- https://www.eshlomo.us/apt-group-exploited-unpatched-0-day-in-ie/
- https://www.bleepingcomputer.com/news/security/internet-explorer-zero-day-exploited-in-the-wild-by-a...
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8174