RULE(RULE ID:712748)

Rule General Information
Release Date: 2020-12-29
Rule Name: Microsoft Windows VBScript Engine Memory Corruption Vulnerability (CVE-2018-8174)
Severity:
CVE ID:
Rule Protection Details
Description: A memory corruption vulnerability exists in the Microsoft Windows VBScript engine. The vulnerability is due to the way that the VBScript engine handles certain objects in memory. A remote attacker can exploit this vulnerability by enticing a user to open a crafted web page using Internet Explorer or a crafted Microsoft Office document.
Impact: An attacker can execute arbitrary code in the context of the vulnerable system. Failed exploit may cause denial-of-service attack.
Affected OS: Windows
Reference: SecurityFocusBID:103998
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8174
https://blog.0patch.com/2018/05/a-single-instruction-micropatch-for.html
ExploitDB:44741
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8174