CVE-2018-8260
published 2018-07-11CVE-2018-8260: A Remote Code Execution vulnerability exists in .NET software when the software fails to check the source markup of a file, aka ".NET Framework Remote Code…
PriorityP357high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
14.58%
96.3th percentile
A Remote Code Execution vulnerability exists in .NET software when the software fails to check the source markup of a file, aka ".NET Framework Remote Code Execution Vulnerability." This affects .NET Framework 4.7.2, Microsoft .NET Framework 4.7.2.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_net_framework | — | — |
| microsoft | microsoft_net_framework | — | — |
| microsoft | microsoft_net_framework | — | — |
| microsoft | microsoft_net_framework | — | — |
| microsoft | microsoft_net_framework | — | — |
| microsoft | microsoft_net_framework | — | — |
| microsoft | microsoft_net_framework | — | — |
| microsoft | microsoft_net_framework | — | — |
| microsoft | microsoft_net_framework | — | — |
| microsoft | microsoft_net_framework | — | — |
| microsoft | microsoft_net_framework | — | — |
| microsoft | microsoft_net_framework | — | — |
| microsoft | microsoft_net_framework | — | — |
| microsoft | microsoft_net_framework | — | — |
| microsoft | microsoft_net_framework | — | — |
| microsoft | microsoft_net_framework | — | — |
| microsoft | microsoft_net_framework | — | — |
| microsoft | microsoft_net_framework | — | — |
| microsoft | microsoft_net_framework | — | — |
| microsoft | microsoft_net_framework | — | — |
| microsoft | microsoft_net_framework | — | — |
| microsoft | microsoft_net_framework | — | — |
| microsoft | microsoft_net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Vulnerability is triggered when a user opens a specially crafted file with an affected version of .NET Framework; monitor for unexpected file opens leading to code execution under .NET Framework 4.7.2 processes ↗
- →In an email attack scenario, watch for spear-phishing emails delivering specially crafted files targeting .NET Framework 4.7.2 users ↗
- →The vulnerability stems from failure to check source markup of a file in .NET Framework; consider monitoring XAML/markup file parsing activity in .NET Framework 4.7.2 applications ↗
- ·Affects specifically .NET Framework 4.7.2; Windows 10 version 1709 and earlier require an additional fix delivered via Windows Update or the .NET Framework 4.7.2 Web Installer ↗
- ·Exploit status is publicly disclosed: No; Exploited: No; rated Exploitation Unlikely for both latest and older software releases — lower priority for emergency response but patching is still required ↗
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
.NET Framework Remote Code Execution Vulnerability
vendor_msrc·2018-07-10·CVSS 8.8
CVE-2018-8260 [HIGH] .NET Framework Remote Code Execution Vulnerability
.NET Framework Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file.
An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
Exploitation of the vulnerability requires that a user open a specially crafted file with an affecte
GHSA
GHSA-q76h-pfpm-pgpp: A Remote Code Execution vulnerability exists in
ghsa_unreviewed·2022-05-14
CVE-2018-8260 [HIGH] CWE-20 GHSA-q76h-pfpm-pgpp: A Remote Code Execution vulnerability exists in
A Remote Code Execution vulnerability exists in .NET software when the software fails to check the source markup of a file, aka ".NET Framework Remote Code Execution Vulnerability." This affects .NET Framework 4.7.2, Microsoft .NET Framework 4.7.2.
No detection rules found.
No public exploits indexed.
Talos
Microsoft Patch Tuesday - July 2018
blogs_talos·2018-07-10·CVSS 7.5
[HIGH] Microsoft Patch Tuesday - July 2018
Microsoft released its monthly set of security advisories today for vulnerabilities that have been identified and addressed in various products. This month's release addresses 53 new vulnerabilities, 17 of which are rated critical, 34 are rated important, one is rated moderate, and one is rated as low severity. These vulnerabilities impact Windows Operating System, Edge, Internet Explorer and more.
In addition to the 53 vulnerabilities referenced above, Microsoft has also released a critical update advisory, ADV180017, which addresses the vulnerabilities described in the Adobe security bulletin APSB18-24.
## Critical vulnerabilitiesThis month, Microsoft is addressing 17 vulnerabilities that are rated as critical:
CVE-2018-8242 - Scripting Engine Memory Corruption Vulnerability
CVE-2018-
Talos
Microsoft Patch Tuesday - July 2018
blogs_talos·2018-07-10·CVSS 7.5
[HIGH] Microsoft Patch Tuesday - July 2018
## Microsoft Patch Tuesday - July 2018
Microsoft released its monthly set of security advisories today for vulnerabilities that have been identified and addressed in various products. This month's release addresses 53 new vulnerabilities, 17 of which are rated critical, 34 are rated important, one is rated moderate, and one is rated as low severity. These vulnerabilities impact Windows Operating System, Edge, Internet Explorer and more.
In addition to the 53 vulnerabilities referenced above, Microsoft has also released a critical update advisory, ADV180017 , which addresses the vulnerabilities described in the Adobe security bulletin APSB18-24 .
## Critical vulnerabilities This month, Microsoft is addressing 17 vulnerabilities that are rated as critical:
CVE-2018-8242 - Scripting Engin
http://www.securityfocus.com/bid/104666http://www.securitytracker.com/id/1041257https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8260http://www.securityfocus.com/bid/104666http://www.securitytracker.com/id/1041257https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8260
2018-07-11
Published