CyberSec.Space Logo
Back to CVE Browser

CVE-2018-0824

Known Exploited (CISA KEV)HIGH
8.8
CVSS Severity Score
EPSS Score50.8340%
EPSS Percentile86.41th
PublishedMay 9, 2018
Last ModifiedOct 28, 2025

Vulnerability Description

A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized objects, aka "Microsoft COM for Windows Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.

Affected Platforms (CPE)

πŸ’»
Microsoft

Windows 10 1507

All versions
πŸ’»
Microsoft

Windows 10 1607

All versions
πŸ’»
Microsoft

Windows 10 1703

All versions
πŸ’»
Microsoft

Windows 10 1709

All versions
πŸ’»
Microsoft

Windows 10 1803

All versions
πŸ’»
Microsoft

Windows 7

All versions
πŸ’»
Microsoft

Windows 8.1

All versions
πŸ’»
Microsoft

Windows Rt 8.1

All versions
πŸ’»
Microsoft

Windows Server 1709

All versions
πŸ’»
Microsoft

Windows Server 1803

All versions
πŸ’»
Microsoft

Windows Server 2008

All versions
πŸ’»
Microsoft

Windows Server 2008

= r2
πŸ’»
Microsoft

Windows Server 2008

= r2
πŸ’»
Microsoft

Windows Server 2012

All versions
πŸ’»
Microsoft

Windows Server 2012

= r2
πŸ’»
Microsoft

Windows Server 2016

All versions

References & Advisories

Related Vulnerabilities