CVE-2018-8174

HIGH KEV RANSOMWARE

Windows VBScript Engine - RCE

Title source: llm

Description

A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.

Exploits (21)

github WRITEUP 3,480 stars
by qazbnm456 · poc
https://github.com/qazbnm456/awesome-cve-poc/tree/master/CVE-2018-8174.md
nomisec WORKING POC 169 stars
by 0x09AL · client-side
https://github.com/0x09AL/CVE-2018-8174-msf
nomisec WORKING POC 141 stars
by Yt1g3r · client-side
https://github.com/Yt1g3r/CVE-2018-8174_EXP
nomisec WRITEUP 31 stars
by piotrflorczyk · client-side
https://github.com/piotrflorczyk/cve-2018-8174_analysis
github WRITEUP 14 stars
by xbl3 · poc
https://github.com/xbl3/awesome-cve-poc_qazbnm456/tree/master/CVE-2018-8174.md
nomisec WORKING POC 9 stars
by ruthlezs · client-side
https://github.com/ruthlezs/ie11_vbscript_exploit
nomisec WORKING POC 7 stars
by SyFi · client-side
https://github.com/SyFi/CVE-2018-8174
nomisec WRITEUP 1 stars
by orf53975 · poc
https://github.com/orf53975/Rig-Exploit-for-CVE-2018-8174
nomisec WORKING POC
by ericisnotrealname · remote
https://github.com/ericisnotrealname/CVE-2018-8174_EXP
nomisec WORKING POC
by lisinan988 · client-side
https://github.com/lisinan988/CVE-2018-8174-exp
nomisec WORKING POC
by likekabin · poc
https://github.com/likekabin/CVE-2018-8174-msf
exploitdb WORKING POC
by smgorelik · htmllocalwindows
https://www.exploit-db.com/exploits/44741
patchapalooza WORKING POC
by 0x1 · remote
https://gitlab.com/0x1/CVE-2018-8174

Scores

CVSS v3 7.5
EPSS 0.9428
EPSS Percentile 99.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Exploitation Intel

CISA KEV 2022-02-15
VulnCheck KEV 2018-05-08
InTheWild.io 2018-05-08
ENISA EUVD EUVD-2018-19844
Ransomware Use Confirmed

Classification

CWE
CWE-787
Status published

Affected Products (13)

microsoft/windows_10_1607
microsoft/windows_10_1703
microsoft/windows_10_1709
microsoft/windows_10_1803
microsoft/windows_7
microsoft/windows_8.1
microsoft/windows_rt_8.1
microsoft/windows_server_2008
microsoft/windows_server_2008
microsoft/windows_server_2008
microsoft/windows_server_2012
microsoft/windows_server_2012
microsoft/windows_server_2016

Timeline

Published May 09, 2018
KEV Added Feb 15, 2022
Tracked Since Feb 18, 2026