cbcvebase.
CVE-2018-8260
published 2018-07-11

CVE-2018-8260: A Remote Code Execution vulnerability exists in .NET software when the software fails to check the source markup of a file, aka ".NET Framework Remote Code…

PriorityP357high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
14.58%
96.3th percentile
A Remote Code Execution vulnerability exists in .NET software when the software fails to check the source markup of a file, aka ".NET Framework Remote Code Execution Vulnerability." This affects .NET Framework 4.7.2, Microsoft .NET Framework 4.7.2.

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftnet_framework
microsoftnet_framework

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability is triggered when a user opens a specially crafted file with an affected version of .NET Framework; monitor for unexpected file opens leading to code execution under .NET Framework 4.7.2 processes
  • In an email attack scenario, watch for spear-phishing emails delivering specially crafted files targeting .NET Framework 4.7.2 users
  • The vulnerability stems from failure to check source markup of a file in .NET Framework; consider monitoring XAML/markup file parsing activity in .NET Framework 4.7.2 applications
  • ·Affects specifically .NET Framework 4.7.2; Windows 10 version 1709 and earlier require an additional fix delivered via Windows Update or the .NET Framework 4.7.2 Web Installer
  • ·Exploit status is publicly disclosed: No; Exploited: No; rated Exploitation Unlikely for both latest and older software releases — lower priority for emergency response but patching is still required

CVSS provenance

nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.