Skip to main content

CVE detail

CVE-2018-8174

A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.

CVSS 7.5 · HighBuzz score 75.0KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 75.0

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 30.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
30.0
60 evidence mentions in the snapshot
Diversity score
20.0
11 sources across 5 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
60 source links · newest first
  • The right tool can make or break a pentest or red team exercise. While many of the tools in Kali are tried and true, they are not always the best fit for every scenario. It is crucial to know where to turn for different needs, ensuring you’re adequately equipped to meet a variety of objectives. […]

    newswww.csoonline.comOct 2, 2024, 10:00 AM
  • Old vulnerabilities are still a big problemHelp Net Security

    A recently flagged phishing campaign aimed at delivering the Agent Tesla RAT to unsuspecting users takes advantage of old vulnerabilities in Microsoft Office that allow remote code execution. “Despite fixes for CVE-2017-11882/CVE-2018-0802 being released by Microsoft in November, 2017 and January, 2018, this vulnerability remains popular amongst threat actors, suggesting there are still unpatched devices in the wild, even after over five years,” says Fortinet researcher Xiaopeng Zhang. “We are observing and mitigating 3000 attacks … More →

    newswww.helpnetsecurity.comSep 6, 2023, 1:51 PM
  • The United States Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday announced that it has expanded its Known Exploited Vulnerabilities Catalog with nine more security flaws, including two recently addressed zero-days.

    newswww.securityweek.comFeb 16, 2022, 12:52 PM
  • The U.S. CISA added to the Known Exploited Vulnerabilities Catalog another 9 security flaws actively exploited in the wild. US Cybersecurity and Infrastructure Security Agency (CISA) added nine new vulnerabilities to its Known Exploited Vulnerabilities Catalog, including two recently patched zero-day issues affecting Adobe Commerce/Magento Open Source and Google Chrome. CISA orders all Federal Civilian Executive […]

    newssecurityaffairs.comFeb 16, 2022, 10:04 AM
  • What is Egregor?Egregor ransomware is a relatively new ransomware (first spotted in September 2020) that seems intent on making its way…

    newswww.malwarebytes.comDec 14, 2020, 5:00 PM
  • In 2019, Microsoft Office became cybercriminals’ preferred platform when carrying out attacks, and the number of incidents keeps increasing, according to Kaspersky Lab researchers. Boris Larin, Vlad Stolyarov and Alexander Liskin showed at the company’s Security Analyst Summit that the threat landscape has changed in the past two years and urged users to keep their software […]

    newswww.csoonline.comJul 24, 2020, 10:00 AM
  • We've detected an uptick in Maze ransomware samples across multiple industries and created a general threat assessment post on the group behind it.

    vendorunit42.paloaltonetworks.comMay 8, 2020, 1:00 PM
  • Which ten software vulnerabilities should you patch as soon as possible (if you haven’t already)? Table of top exploited CVEs between 2016 and 2019 (repeats are noted by color) Recorded Future researchers have analyzed code repositories, underground forum postings, dark web sites, closed source reports and data sets comprising of submissions to popular malware repositories to compile a list of the ten most exploited vulnerabilities by cybercriminals in 2019. The list The list is comprised … More →

    newswww.helpnetsecurity.comFeb 6, 2020, 6:30 AM
  • Exploit kits: fall 2019 reviewMalwarebytes Labs

    Despite a slim browser market share, Internet Explorer is still being exploited in fall 2019 in a number of drive-by download…

    newswww.malwarebytes.comNov 18, 2019, 5:00 PM
  • The recently discovered ransomware-as-a-service (RaaS) Buran attempts to gain popularity by offering discounted licenses. In May, researchers from McAfee’s Advanced Threat Research Team discovered a new piece of ransomware named ‘Buran.’ Buran is offered as a RaaS model, but unlike other ransomware families such as REVil, GandCrab the authors take 25% of the income earned […]

    newssecurityaffairs.comNov 12, 2019, 1:15 PM
  • A recently discovered exploit kit dubbed Capesand is being involved in live attacks despite the fact that it’s still under development. In October 2019, researchers at TrendMicro discovered a new exploit kit dubbed Capesand that is being involved in live attacks. The tool was discovered while analyzing a malvertising campaign employing the RIG EK to […]

    newssecurityaffairs.comNov 8, 2019, 11:01 AM
  • A newly discovered exploit kit (EK) is being employed in live attacks despite the fact that it’s still in an unfinished state, Trend Micro’s security researchers reveal.

    newswww.securityweek.comNov 8, 2019, 7:29 AM
  • The 5th installment in a series of posts tracking web-based threats over time from our Email Link Analysis (ELINK) system., specifically, statistics pertaining to malicious URLs, domains, exploit kits, vulnerabilities, and phishing scams.

    vendorunit42.paloaltonetworks.comNov 1, 2019, 1:00 PM
  • Exploit kits: summer 2019 reviewMalwarebytes Labs

    In the months since our last spring review, there has been some interesting activity from several exploit kits. While the playing…

    newswww.malwarebytes.comJul 29, 2019, 5:00 PM
  • The threat actor behind the SLUB backdoor has started abusing a recently patched Internet Explorer vulnerability for distribution purposes, Trend Micro’s security researchers reveal.

    newswww.securityweek.comJul 17, 2019, 2:40 PM
  • Researchers at Cisco Talos group have discovered a new exploit kit dubbed Spelevo that spreads via a compromised business-to-business website. Malware researchers at Cisco Talos have discovered a new exploit kit dubbed Spelevo that spreads via a compromised business-to-business website. The popularity of EK rapidly decreased with the demise of the Angler Exploit Kit, but the discovery […]

    newssecurityaffairs.comJun 29, 2019, 5:08 AM
  • A newly discovered exploit kit is being disseminated via a compromised business-to-business website, Cisco Talos security researchers report.

    newswww.securityweek.comJun 28, 2019, 2:07 PM
  • Our latest research evaluates the data from our Email Link Analysis (ELINK) system and shows France rises to number one for malicious URL hosting, the US to number one for phishing for Web-based threats in the last quarter of 2018. Learn more details in the full report.

    vendorunit42.paloaltonetworks.comMay 30, 2019, 4:00 PM
  • Exploit kits: spring 2019 reviewMalwarebytes Labs

    Exploit kit activity remains fairly unchanged since our last winter review in terms of active distribution campaigns. But this spring edition…

    newswww.malwarebytes.comMay 13, 2019, 5:00 PM
  • In February 2019, Unit 42 published a blog about the BabyShark malware family and the associated spear phishing campaigns targeting U.S. national think tanks. Since that publication, malicious attacks leveraging BabyShark have continued through March and April 2019. The attackers expanded targeting to the cryptocurrency industry, showing that those behind these attacks also have interests in financial gain.

    vendorunit42.paloaltonetworks.comApr 26, 2019, 6:40 PM
  • A group of hackers is using a previously undocumented backdoor program designed to interact with attackers over Slack. While abusing legitimate services for malware command-and-control purposes is not a new development, this is the first time researchers have seen Slack, a popular enterprise collaboration tool, being used in this way. The backdoor was detected by […]

    newswww.csoonline.comMar 11, 2019, 2:07 PM
  • Malware researchers from Trend Micro have spotted a new piece of malware dubbed SLUB that leverages GitHub and Slack for C&C communications. Malware researchers at Trend Micro have spotted a new backdoor dubbed SLUB that abuse GitHub and Slack for command and control (C&C) communications. According to the experts, the SLUB backdoor (Backdoor.Win32.SLUB.A) was only […]

    newssecurityaffairs.comMar 9, 2019, 5:53 AM
  • Researchers from Trend Micro have come across a new piece of malware that abuses GitHub and Slack for command and control (C&C) communications.

    newswww.securityweek.comMar 8, 2019, 2:22 PM
  • A malicious campaign attempting to infect business users in the United States with a backdoor has been ongoing for over half a year, Proofpoint reports.

    newswww.securityweek.comFeb 26, 2019, 11:17 AM
  • Exploit kits: winter 2019 reviewMalwarebytes Labs

    Active malvertising campaigns in December and the new year have kept exploit kit activity from hibernating in winter 2019. We mostly…

    newswww.malwarebytes.comFeb 11, 2019, 5:00 PM
  • Our Email Link Analysis (ELINK) system is routinely reviewed by our Unit 42 research team. In examining the data it collects, patterns and trends are discovered which helps us discern prevalent web threats. This blog is the third (3rd quarter of 2018) in a series of posts tracking web-based threats throughout the year, specifically statistics pertaining to malicious URLs, domains, exploit kits, and CVEs.

    vendorunit42.paloaltonetworks.comDec 27, 2018, 2:00 PM
  • One of the most interesting exploit kits we track is also a bit of an elusive one, and as such does…

    newswww.malwarebytes.comDec 20, 2018, 5:00 PM
  • New Wine in Old Bottle: New Azorult Variant Found in FindMyName Campaign using Fallout Exploit Kit.

    vendorunit42.paloaltonetworks.comNov 21, 2018, 4:00 AM
  • Exploit kits: fall 2018 reviewMalwarebytes Labs

    Exploit kit (EK) activity continues to surprise us as the weather cools, the leaves change, and we move into the fall of…

    newswww.malwarebytes.comOct 23, 2018, 5:00 PM
  • A variant of a remote code execution vulnerability with Internet Explorer’s scripting engine known as CVE-2018-8373 patched last August has been found in…

    newswww.malwarebytes.comSep 25, 2018, 5:00 PM
  • The Russian Cobalt crime gang was particularly active in the last month, a new report confirms a massive use of the CobInt malware in recent attacks. Security researchers from Proofpoint reported the massive use of the CobInt malware by the Cobalt group in recent attacks. The Cobalt name is based on the association of the […]

    newssecurityaffairs.comSep 13, 2018, 7:56 AM
  • The Russia-based Cobalt hacking group has made heavy use of the CobInt malware in recently observed campaigns, Proofpoint’s security researchers warn.

    newswww.securityweek.comSep 12, 2018, 11:42 PM
  • At the end of August, security experts discovered a new exploit kit called Fallout that is being used to distribute the GandCrab ransomware. At the end of August, the threat analyst nao_sec discovered a new exploit kit called Fallout that is being used to distribute the GandCrab ransomware and other malicious codes, including droppers and potentially unwanted […]

    newssecurityaffairs.comSep 10, 2018, 7:09 AM
  • A recently discovered exploit kit (EK) has been used in a campaign targeting users in Japan, Korea, the Middle East, Southern Europe, and other countries in the Asia Pacific region.

    newswww.securityweek.comSep 7, 2018, 5:57 PM
  • Unit 42 details how advanced endpoint protection can prevent in-the-wild VBScript Zero-day exploit in Internet Explorer.

    vendorunit42.paloaltonetworks.comSep 7, 2018, 12:00 PM
  • Email Link Analysis from Unit 42 reveals that the United States remain the number one hoster of malicious web addresses for Q2 2018.

    vendorunit42.paloaltonetworks.comSep 5, 2018, 3:12 AM
  • North Koren hackers are exploiting a recently patched vulnerability in Microsoft’s VBScript engine vulnerability

    newswww.securityweek.comAug 20, 2018, 6:47 PM
  • The North Korea-linked Dark Hotel APT group is leveraging the recently patched CVE-2018-8373 vulnerability in the VBScript engine in attacks in the wild. The vulnerability affects Internet Explorer 9, 10 and 11, it was first disclosed last month by Trend Micro and affected all supported versions of Windows. The flaw could be exploited by remote attackers […]

    newssecurityaffairs.comAug 19, 2018, 3:58 PM
  • In the August 2018 Patch Tuesday, Microsoft has plugged over 60 vulnerabilities, two of which are being actively exploited in the wild. In addition to those, the company has also released a critical update advisory that addresses vulnerabilities found and patched in Adobe Flash. Exploited zero-days The two patched zero-days are: CVE-2018-8414 – A vulnerability in Windows Shell that can be triggered by a user opening a specially crafted file and could allow the attacker … More →

    newswww.helpnetsecurity.comAug 15, 2018, 2:46 PM
  • Microsoft’s Patch Tuesday updates for August 2018 address 60 vulnerabilities, including two zero-day flaws affecting Windows and Internet Explorer.

    newswww.securityweek.comAug 15, 2018, 5:34 AM
  • Exploit kits: summer 2018 reviewMalwarebytes Labs

    The uptick trend in cybercriminals using exploit kits that we first noticed in our spring 2018 report has continued into the summer….

    newswww.malwarebytes.comAug 6, 2018, 5:00 PM
  • This blog post was authored by @hasherezade and Jérôme Segura.We recently detected a drive-by download attack trying to exploit CVE-2018-4878, a vulnerability in Flash…

    newswww.malwarebytes.comJul 25, 2018, 5:00 PM
  • Unit 42 Threat Brief: Office Documents can be dangerous, however, we'll continue to use them anyway.

    vendorunit42.paloaltonetworks.comJul 24, 2018, 12:00 PM
  • Magniber ransomware improves, expands within AsiaMalwarebytes Labs

    This blog post was authored by @hasherezade and Jérôme Segura.The Magnitude exploit kit is one of the longest-serving browser exploitation toolkits…

    newswww.malwarebytes.comJul 15, 2018, 5:00 PM
  • Cyber criminal organizations and state-sponsored hackers continue to use Exploit kits to compromise targets world worldwide if the use of Exploit kits is decreased across the recent months, some of them were improved by adding the code to exploit recently discovered Flash and Internet Explorer zero-day vulnerabilities. “Since both Flash and the VBScript engine are […]

    newssecurityaffairs.comJun 14, 2018, 7:06 AM
  • Exploit kits (EKs) might not be as dominant as they were several years ago, but they continue to exist and most of them already adopted exploits for recently discovered Flash and Internet Explorer zero-day vulnerabilities.

    newswww.securityweek.comJun 13, 2018, 3:50 PM
  • Exploit kits: Spring 2018 reviewMalwarebytes Labs

    Since our last report on exploit kits, there have been some new developments with the wider adoption of the February Flash…

    newswww.malwarebytes.comJun 11, 2018, 5:00 PM
  • A new round of the weekly SecurityAffairs newsletter arrived! The best news of the week with Security Affairs. Let me inform you that my new book, “Digging in the Deep Web” is online Kindle Edition Paper Copy Once again thank you! Crooks included the code for CVE-2018-8174 IE Zero-Day in the RIG Exploit Kit Impervas […]

    newssecurityaffairs.comJun 10, 2018, 4:57 AM
  • Cyber criminals recently added the code for the CVE-2018-8174 Internet Explorer zero-day vulnerability to the infamous RIG exploit kit. Crooks recently added the code for an Internet Explorer zero-day vulnerability to the infamous RIG exploit kit. The Internet Explorer zero-day vulnerability, tracked as CVE-2018-8174, was first discovered a few weeks ago, it affects VBScript implemented in Internet Explorer and Microsoft […]

    newssecurityaffairs.comJun 3, 2018, 7:32 AM
  • During the first half of 2018, we have witnessed some particularly interesting zero-day exploits, including one for Flash (CVE-2018-4878) and more recently…

    newswww.malwarebytes.comMay 14, 2018, 5:00 PM
  • A new round of the weekly SecurityAffairs newsletter arrived! The best news of the week with Security Affairs. Let me inform you that my new book, “Digging in the Deep Web” is online Kindle Edition Paper Copy Once again thank you! · European Central Bank announced a framework for cyber attack simulation on financial firms […]

    newssecurityaffairs.comMay 13, 2018, 5:47 PM
  • Recently, the Advanced Threat Response Team of 360 Core Security Division detected an APT attack exploiting a 0-day vulnerability tracked as CVE-2018-8174. Now the experts published a detailed analysis of the flaw. I Overview Recently, the Advanced Threat Response Team of 360 Core Security Division detected an APT attack exploiting a 0-day vulnerability and captured the world’s […]

    newssecurityaffairs.comMay 10, 2018, 5:31 AM
  • No excerpt available.

    Mitigationwww.cisa.govMay 9, 2018, 7:29 PM
  • https://www.exploit-db.com/exploits/44741/www.exploit-db.com

    No excerpt available.

    Exploitwww.exploit-db.comMay 9, 2018, 7:29 PM
  • No excerpt available.

    Vendor Advisoryportal.msrc.microsoft.comMay 9, 2018, 7:29 PM
  • No excerpt available.

    Exploitblog.0patch.comMay 9, 2018, 7:29 PM
  • http://www.securityfocus.com/bid/103998www.securityfocus.com

    No excerpt available.

    Exploitwww.securityfocus.comMay 9, 2018, 7:29 PM
  • Update (2018-06-04): CVE-2018-8174 has been added to the Magnitude exploit kit (Source: MDNC).Update (2018-05-25): CVE-2018-8174 has been added to the RIG exploit…

    newswww.malwarebytes.comMay 9, 2018, 5:00 PM
  • Microsoft has released the May 2018 Patch Tuesday that addresses more than 60 vulnerabilities, including two Windows zero-day flaws that can be exploited for remote code execution and privilege escalation. Microsoft May 2018 Patch Tuesday includes security patches for 67 vulnerabilities, including two zero-days that have already been exploited in the wild by threat actors. The […]

    newssecurityaffairs.comMay 9, 2018, 8:08 AM
  • Microsoft has fixed more than 60 vulnerabilities with its May 2018 Patch Tuesday updates, including two Windows zero-day flaws that can be exploited for remote code execution and privilege escalation.

    newswww.securityweek.comMay 8, 2018, 7:37 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence