CVE-2018-8113
published 2018-06-14CVE-2018-8113: A security feature bypass vulnerability exists in Internet Explorer that allows for bypassing Mark of the Web Tagging (MOTW), aka "Internet Explorer Security…
PriorityP333medium6.5CVSS 3.0
AVNACLPRNUIRSUCNIHAN
EPSS
4.93%
91.2th percentile
A security feature bypass vulnerability exists in Internet Explorer that allows for bypassing Mark of the Web Tagging (MOTW), aka "Internet Explorer Security Feature Bypass Vulnerability." This affects Internet Explorer 11.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| msrc | internet_explorer_11_on_windows_10_version_1703_for_32-bit_systems | — | — |
| msrc | internet_explorer_11_on_windows_10_version_1703_for_x64-based_systems | — | — |
| msrc | internet_explorer_11_on_windows_10_version_1709_for_32-bit_systems | — | — |
| msrc | internet_explorer_11_on_windows_10_version_1709_for_x64-based_systems | — | — |
| msrc | internet_explorer_11_on_windows_10_version_1803_for_32-bit_systems | — | — |
| msrc | internet_explorer_11_on_windows_10_version_1803_for_x64-based_systems | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_msrc4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9695-mmhq-42p6: A security feature bypass vulnerability exists in Internet Explorer that allows for bypassing Mark of the Web Tagging (MOTW), aka "Internet Explorer S
ghsa_unreviewed·2022-05-13
CVE-2018-8113 [MEDIUM] GHSA-9695-mmhq-42p6: A security feature bypass vulnerability exists in Internet Explorer that allows for bypassing Mark of the Web Tagging (MOTW), aka "Internet Explorer S
A security feature bypass vulnerability exists in Internet Explorer that allows for bypassing Mark of the Web Tagging (MOTW), aka "Internet Explorer Security Feature Bypass Vulnerability." This affects Internet Explorer 11.
Microsoft
Internet Explorer Security Feature Bypass Vulnerability
vendor_msrc·2018-06-12·CVSS 4.3
CVE-2018-8113 [MEDIUM] Internet Explorer Security Feature Bypass Vulnerability
Internet Explorer Security Feature Bypass Vulnerability
Description: A security feature bypass vulnerability exists in Internet Explorer that allows for bypassing Mark of the Web Tagging (MOTW). Failing to set the MOTW means that a large number of Microsoft security technologies are bypassed.
In a web-based attack scenario, an attacker could host a malicious website that is designed to exploit the security feature bypass. Alternatively, in an email or instant message attack scenario, the attacker could send the targeted user a specially crafted .url file that is designed to exploit the bypass. Additionally, compromised websites or websites that accept or host user-provided content could contain specially crafted content to exploit the security feature bypass. However, in all cases an atta
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/104365http://www.securitytracker.com/id/1041099https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8113http://www.securityfocus.com/bid/104365http://www.securitytracker.com/id/1041099https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8113
2018-06-14
Published