cbcvebase.
CVE-2018-8420
published 2018-09-13

CVE-2018-8420: A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka "MS XML Remote Code Execution…

PriorityP263high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
48.90%
98.7th percentile
A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka "MS XML Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.

Affected

54 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10_servers
microsoftwindows_10_servers
microsoftwindows_7
microsoftwindows_7
microsoftwindows_8.1
microsoftwindows_8.1
microsoftwindows_rt_8.1
microsoftwindows_server
microsoftwindows_server
microsoftwindows_server
microsoftwindows_server

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability is triggered when MSXML parser processes user input via Internet Explorer parsing XML content — monitor for IE invoking MSXML through web browser interactions with untrusted/external XML content
  • Attack vector is user clicking a malicious link delivered via email or instant message leading to a crafted website that invokes MSXML — monitor for IE spawning child processes or unusual MSXML activity following link clicks
  • Exploitation assessed as 'More Likely' for both latest and older software releases — prioritize detection and patching on all supported Windows versions including Windows 7, 8.1, 10, Server 2008/2012/2016
  • ·No in-the-wild exploitation confirmed at time of disclosure; however, exploitation likelihood is rated 'More Likely' for all release tracks — treat as high-priority patching target
  • ·The vulnerability resides in Microsoft XML Core Services (MSXML) parser input handling; the fix corrects input processing logic — unpatched systems remain exposed to remote code execution via crafted XML

CVSS provenance

nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_msrc7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.