CVE-2018-0824 - Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability
Project:Microsoft
Product:Windows
Date Added:2024-08-05Due Date:2024-08-26
Vulnerability Name
Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability
Description
Microsoft COM for Windows contains a deserialization of untrusted data vulnerability that allows for privilege escalation and remote code execution via a specially crafted file or script.
Known To Be Used in Ransomware Campaigns?
Unknown
Action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Additional Notes
https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2018-0824
https://nvd.nist.gov/vuln/detail/CVE-2018-0824
Related News Articles
Google Patches New Android Kernel Vulnerability Exploited in the WildAugust 6, 2024
APT41 Hackers Use ShadowPad, Cobalt Strike in Taiwanese Institute Cyber AttackAugust 3, 2024