CVE-2018-8552
high · 7.5An information disclosure vulnerability exists when VBScript improperly discloses the contents of its memory, which could provide an attacker with information to further compromise the user's computer or data, aka "Windows Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10.
7.5
CVSS
51.0%
EPSS (exploit prob.)
99th
EPSS percentile
2018-11-14
Published
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Weaknesses
CWE-119
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | internet_explorer | 11 |
| microsoft | windows_10 | all versions |
| microsoft | windows_10 | 1607 |
| microsoft | windows_10 | 1703 |
| microsoft | windows_10 | 1709 |
| microsoft | windows_10 | 1803 |
| microsoft | windows_10 | 1809 |
| microsoft | windows_7 | all versions |
| microsoft | windows_8.1 | all versions |
| microsoft | windows_rt_8.1 | all versions |
| microsoft | windows_server_2008 | r2 |
| microsoft | windows_server_2012 | r2 |
| microsoft | windows_server_2016 | all versions |
| microsoft | windows_server_2019 | all versions |
| microsoft | internet_explorer | 10 |
| microsoft | windows_server_2012 | all versions |
| microsoft | internet_explorer | 9 |
| microsoft | windows_server_2008 | all versions |
Check a specific version with /api/v1/cve/match.
References
- http://www.securityfocus.com/bid/105786
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8552
- https://www.exploit-db.com/exploits/45924/
- http://www.securityfocus.com/bid/105786
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8552
- https://www.exploit-db.com/exploits/45924/
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2018-8552