← Back to browse · API

CVE-2018-0824

Severity
HIGH
CVSS
7.5
EPSS
0.72405
Risk score
80.34
CISA KEV
Yes
PoC
No
Published
2024-08-05
Modified
2024-08-05
First seen
2026-08-07
Aliases
EUVD-2018-1629, GHSA-6W8G-777W-9MCC
Products
Microsoft:Windows, n/a:n/a n/a
Sources
euvd EUVD-2018-1629
cisa.gov CVE-2018-0824

Description

Microsoft COM for Windows contains a deserialization of untrusted data vulnerability that allows for privilege escalation and remote code execution via a specially crafted file or script.

References