CVE-2018-8174
HIGH KEV RANSOMWAREWindows VBScript Engine - RCE
Title source: llmDescription
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
Exploits (21)
github
WRITEUP
3,480 stars
by qazbnm456 · poc
https://github.com/qazbnm456/awesome-cve-poc/tree/master/CVE-2018-8174.md
github
34 stars
by DarkFunct · cpoc
https://github.com/DarkFunct/CVE_Exploits/tree/main/CVE-2018-8174
nomisec
WRITEUP
31 stars
by piotrflorczyk · client-side
https://github.com/piotrflorczyk/cve-2018-8174_analysis
github
WRITEUP
14 stars
by xbl3 · poc
https://github.com/xbl3/awesome-cve-poc_qazbnm456/tree/master/CVE-2018-8174.md
nomisec
WORKING POC
9 stars
by ruthlezs · client-side
https://github.com/ruthlezs/ie11_vbscript_exploit
nomisec
WORKING POC
by ericisnotrealname · remote
https://github.com/ericisnotrealname/CVE-2018-8174_EXP
nomisec
by www201001 · poc
https://github.com/www201001/https-github.com-iBearcat-CVE-2018-8174_EXP.git-
nomisec
by sinisterghost · poc
https://github.com/sinisterghost/https-github.com-iBearcat-CVE-2018-8174_EXP
References (5)
Scores
CVSS v3
7.5
EPSS
0.9428
EPSS Percentile
99.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitation Intel
CISA KEV
2022-02-15
VulnCheck KEV
2018-05-08
InTheWild.io
2018-05-08
ENISA EUVD
EUVD-2018-19844
Ransomware Use
Confirmed
Classification
CWE
CWE-787
Status
published
Affected Products (13)
microsoft/windows_10_1607
microsoft/windows_10_1703
microsoft/windows_10_1709
microsoft/windows_10_1803
microsoft/windows_7
microsoft/windows_8.1
microsoft/windows_rt_8.1
microsoft/windows_server_2008
microsoft/windows_server_2008
microsoft/windows_server_2008
microsoft/windows_server_2012
microsoft/windows_server_2012
microsoft/windows_server_2016
Timeline
Published
May 09, 2018
KEV Added
Feb 15, 2022
Tracked Since
Feb 18, 2026