vendor:
Microsoft COM for Windows
by:
Nicolas Joly
7.8
CVSS
HIGH
Remote Code Execution
502
CWE
Product Name: Microsoft COM for Windows
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: YES
Related CWE: None
CPE: None
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows
2018
CVE-2018-0824
A remote code execution vulnerability exists in 'Microsoft COM for Windows' when it fails to properly handle serialized objects. An attacker who successfully exploited the vulnerability could use a specially crafted file or script to perform actions. In an email attack scenario, an attacker could exploit the vulnerability by sending the specially crafted file to the user and convincing the user to open the file. In a web-based attack scenario, an attacker could host a website (or leverage a compromised website that accepts or hosts user-provided content) that contains a specially crafted file that is designed to exploit the vulnerability.
Mitigation:
The security update addresses the vulnerability by correcting how 'Microsoft COM for Windows' handles serialized objects.