7.6

CVE-2018-8552

Exploit
An information disclosure vulnerability exists when VBScript improperly discloses the contents of its memory, which could provide an attacker with information to further compromise the user's computer or data, aka "Windows Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Internet Explorer Version 11 Update -
   Microsoft ≫ Windows 10 Version -
   Microsoft ≫ Windows 10 Version 1607
   Microsoft ≫ Windows 10 Version 1703
   Microsoft ≫ Windows 10 Version 1709
   Microsoft ≫ Windows 10 Version 1803
   Microsoft ≫ Windows 10 Version 1809
   Microsoft ≫ Windows 7 Version - Update sp1
   Microsoft ≫ Windows 8.1 Version -
   Microsoft ≫ Windows Rt 8.1 Version -
   Microsoft ≫ Windows Server 2008 Version r2 Update sp1
   Microsoft ≫ Windows Server 2012 Version r2
   Microsoft ≫ Windows Server 2016 Version -
   Microsoft ≫ Windows Server 2019 Version -
Microsoft ≫ Internet Explorer Version 10
   Microsoft ≫ Windows Server 2012 Version -
Microsoft ≫ Internet Explorer Version 9
   Microsoft ≫ Windows Server 2008 Version - Update sp2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 50.96% 0.988
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 1.6 5.9
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
NIST 7.6 4.9 10
AV:N/AC:H/Au:N/C:C/I:C/A:C
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

http://www.securityfocus.com/bid/105786
Third Party Advisory
VDB Entry
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8552
Patch
Vendor Advisory
https://www.exploit-db.com/exploits/45924/
Third Party Advisory
Exploit
VDB Entry