CVE-2018-8421
published 2018-09-13CVE-2018-8421: A remote code execution vulnerability exists when Microsoft .NET Framework processes untrusted input, aka ".NET Framework Remote Code Execution Vulnerability."…
PriorityP267critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
28.91%
97.9th percentile
A remote code execution vulnerability exists when Microsoft .NET Framework processes untrusted input, aka ".NET Framework Remote Code Execution Vulnerability." This affects Microsoft .NET Framework 4.6, Microsoft .NET Framework 3.5, Microsoft .NET Framework 4.7/4.7.1/4.7.2, Microsoft .NET Framework 3.0, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2, Microsoft .NET Framework 4.7.1/4.7.2, Microsoft .NET Framework 4.7.2, Microsoft .NET Framework 2.0.
Affected
94 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnu | binutils | >= 0 < 2.24-5ubuntu14.2+esm5 | 2.24-5ubuntu14.2+esm5 |
| gnu | binutils | >= 0 < 2.26.1-1ubuntu1~16.04.8+esm9 | 2.26.1-1ubuntu1~16.04.8+esm9 |
| gnu | binutils | >= 0 < 2.30-21ubuntu1~18.04.9+esm3 | 2.30-21ubuntu1~18.04.9+esm3 |
| microsoft | microsoft_net_framework | — | — |
| microsoft | microsoft_net_framework | — | — |
| microsoft | microsoft_net_framework | — | — |
| microsoft | microsoft_net_framework | — | — |
| microsoft | microsoft_net_framework | — | — |
| microsoft | microsoft_net_framework | — | — |
| microsoft | microsoft_net_framework | — | — |
| microsoft | microsoft_net_framework | — | — |
| microsoft | microsoft_net_framework | — | — |
| microsoft | microsoft_net_framework | — | — |
| microsoft | microsoft_net_framework | — | — |
| microsoft | microsoft_net_framework | — | — |
| microsoft | microsoft_net_framework | — | — |
| microsoft | microsoft_net_framework | — | — |
| microsoft | microsoft_net_framework | — | — |
| microsoft | microsoft_net_framework | — | — |
| microsoft | microsoft_net_framework | — | — |
| microsoft | microsoft_net_framework | — | — |
| microsoft | microsoft_net_framework | — | — |
| microsoft | microsoft_net_framework | — | — |
| microsoft | microsoft_net_framework | — | — |
| microsoft | microsoft_net_framework | — | — |
Detection & IOCsextracted from sources · hover to see the quote
url/_vti_bin/webpartpages.asmx
snort
alert http any any -> $HOME_NET any (msg:"ET HUNTING Microsoft Sharepoint Deserialization RCE via Workflow (CVE-2018-8421)"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/_vti_bin/webpartpages.asmx"; http.request_body; content:"|3c|ValidateWorkflowMarkupAndCreateSupportObjects"; fast_pattern; content:"|3c|workflowMarkupText|3e|"; content:"|3c 21 5b|CDATA|5b|"; distance:0; reference:url,www.nccgroup.com/research-blog/technical-advisory-bypassing-microsoft-xoml-workflows-protection-mechanisms-using-deserialisation-of-untrusted-data/; reference:cve,2018-8421; classtype:web-application-attack; sid:2064136; rev:1; metadata:affected_product Microsoft_Sharepoint, attack_target Server, tls_state TLSDecrypt, created_at 2025_08_25, cve CVE_2018_8421, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, tag Exploit, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2025_08_25, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application; target:dest_ip;)
bytes
|3c|ValidateWorkflowMarkupAndCreateSupportObjects
bytes
|3c|workflowMarkupText|3e|
bytes
|3c 21 5b|CDATA|5b|
- →Exploit traffic is a POST request to the SharePoint endpoint /_vti_bin/webpartpages.asmx containing a XOML workflow deserialization payload with ValidateWorkflowMarkupAndCreateSupportObjects and a CDATA-wrapped workflowMarkupText body.
- →The attack vector requires an attacker to upload a specially crafted file to a web application; monitor for suspicious file uploads to .NET-backed web applications. ↗
- →The Snort/Suricata rule (ET sid:2064136) is tagged for TLS-decrypted traffic (tls_state TLSDecrypt), so detection requires TLS inspection at the perimeter or internally.
- ·Red Hat .NET Core packages (1.0, 1.1, 2.0, 2.1 on RHEL) are explicitly marked Not Affected; detection/patching focus should be on Windows .NET Framework installations only. ↗
- ·Microsoft's exploit assessment rates exploitation as 'Less Likely' for both latest and older software releases, and the vulnerability has not been publicly exploited as of the advisory date. ↗
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_msrc9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
NET: RCE when processing untrusted input
vendor_redhat·2018-09-13·CVSS 9.8
CVE-2018-8421 [CRITICAL] CWE-20 NET: RCE when processing untrusted input
NET: RCE when processing untrusted input
A remote code execution vulnerability exists when Microsoft .NET Framework processes untrusted input, aka ".NET Framework Remote Code Execution Vulnerability." This affects Microsoft .NET Framework 4.6, Microsoft .NET Framework 3.5, Microsoft .NET Framework 4.7/4.7.1/4.7.2, Microsoft .NET Framework 3.0, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2, Microsoft .NET Framework 4.7.1/4.7.2, Microsoft .NET Framework 4.7.2, Microsoft .NET Framework 2.0.
Package: rh-dotnetcore10 (.NET Core 1.0 on Red Hat Enterprise Linux) - Not affected
Package: rh-dotnetcore10-dotnetcore (.NET Core 1.0 on Red Hat Enterprise Linux) - Not affec
Microsoft
.NET Framework Remote Code Execution Vulnerability
vendor_msrc·2018-09-11·CVSS 9.8
CVE-2018-8421 [CRITICAL] .NET Framework Remote Code Execution Vulnerability
.NET Framework Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists when Microsoft .NET Framework processes input. An attacker who successfully exploited this vulnerability could take control of an affected system.
To exploit the vulnerability, an attacker would need to be able to upload a specially crafted file to a web application.
The security update addresses the vulnerability by correcting how .NET Framework processes input.
.NET Framework: .NET Framework
Issuing CNA: Microsoft
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4457128
OSV
binutils vulnerabilities
osv·2023-10-04·CVSS 7.8
CVE-2017-17122 binutils vulnerabilities
binutils vulnerabilities
It was discovered that GNU binutils was not properly performing checks
when dealing with memory allocation operations, which could lead to
excessive memory consumption. An attacker could possibly use this issue
to cause a denial of service. This issue only affected Ubuntu 14.04 LTS.
(CVE-2017-17122, CVE-2017-8421)
It was discovered that GNU binutils was not properly performing bounds
checks when processing debug sections with objdump, which could lead to
an overflow. An attacker could possibly use this issue to cause a denial
of service or execute arbitrary code. This issue only affected Ubuntu
14.04 LTS. (CVE-2018-20671, CVE-2018-6543)
It was discovered that GNU binutils contained a reachable assertion, which
could lead to an intentional assertion failure when
GHSA
GHSA-rgxc-r6cp-wvq8: A remote code execution vulnerability exists when Microsoft
ghsa_unreviewed·2022-05-14
CVE-2018-8421 [CRITICAL] CWE-20 GHSA-rgxc-r6cp-wvq8: A remote code execution vulnerability exists when Microsoft
A remote code execution vulnerability exists when Microsoft .NET Framework processes untrusted input, aka ".NET Framework Remote Code Execution Vulnerability." This affects Microsoft .NET Framework 4.6, Microsoft .NET Framework 3.5, Microsoft .NET Framework 4.7/4.7.1/4.7.2, Microsoft .NET Framework 3.0, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2, Microsoft .NET Framework 4.7.1/4.7.2, Microsoft .NET Framework 4.7.2, Microsoft .NET Framework 2.0.
Suricata
ET HUNTING Microsoft Sharepoint Deserialization RCE via Workflow (CVE-2018-8421)
suricata·2025-08-25·CVSS 9.8
CVE-2018-8421 [CRITICAL] ET HUNTING Microsoft Sharepoint Deserialization RCE via Workflow (CVE-2018-8421)
ET HUNTING Microsoft Sharepoint Deserialization RCE via Workflow (CVE-2018-8421)
Rule: alert http any any -> $HOME_NET any (msg:"ET HUNTING Microsoft Sharepoint Deserialization RCE via Workflow (CVE-2018-8421)"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/_vti_bin/webpartpages.asmx"; http.request_body; content:"|3c|ValidateWorkflowMarkupAndCreateSupportObjects"; fast_pattern; content:"|3c|workflowMarkupText|3e|"; content:"|3c 21 5b|CDATA|5b|"; distance:0; reference:url,www.nccgroup.com/research-blog/technical-advisory-bypassing-microsoft-xoml-workflows-protection-mechanisms-using-deserialisation-of-untrusted-data/; reference:cve,2018-8421; classtype:web-application-attack; sid:2064136; rev:1; metadata:affected_product Microsoft_Sharepoint, attack_target Se
No public exploits indexed.
Talos
Microsoft Patch Tuesday - September 2018
blogs_talos·2018-09-11·CVSS 8.4
[HIGH] Microsoft Patch Tuesday - September 2018
Microsoft released its monthly set of security updates today for a variety of its products that address a variety of bugs. The latest Patch Tuesday covers 61 vulnerabilities, 17 of which are rated "critical," 43 that are rated "important" and one that is considered to have "moderate" severity.
The advisories cover bugs in the Internet Explorer web browser, Jet Database Engine and the Chakra scripting engine, among other products and software.
This update also includes two critical advisories, one of which covers security updates to Adobe Flash, and another that deals with a denial-of-service vulnerability in the Microsoft Windows operating system.
## Critical vulnerabilitiesMicrosoft released coverage for 17 critical bugs. Cisco Talos believes 16 of these are of special importance and n
Talos
Microsoft Patch Tuesday - September 2018
blogs_talos·2018-09-11·CVSS 8.4
[HIGH] Microsoft Patch Tuesday - September 2018
## Microsoft Patch Tuesday - September 2018
Microsoft released its monthly set of security updates today for a variety of its products that address a variety of bugs. The latest Patch Tuesday covers 61 vulnerabilities, 17 of which are rated "critical," 43 that are rated "important" and one that is considered to have "moderate" severity.
The advisories cover bugs in the Internet Explorer web browser, Jet Database Engine and the Chakra scripting engine, among other products and software.
This update also includes two critical advisories, one of which covers security updates to Adobe Flash, and another that deals with a denial-of-service vulnerability in the Microsoft Windows operating system.
## Critical vulnerabilities Microsoft released coverage for 17 critical bugs. Cisco Talos believ
Bugzilla
CVE-2018-8421 .NET: RCE when processing untrusted input
bugzilla·2018-09-17·CVSS 9.8
CVE-2018-8421 [CRITICAL] CVE-2018-8421 .NET: RCE when processing untrusted input
CVE-2018-8421 .NET: RCE when processing untrusted input
A remote code execution vulnerability exists when Microsoft .NET Framework processes untrusted input, aka ".NET Framework Remote Code Execution Vulnerability." This affects Microsoft .NET Framework 4.6, Microsoft .NET Framework 3.5, Microsoft .NET Framework 4.7/4.7.1/4.7.2, Microsoft .NET Framework 3.0, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2, Microsoft .NET Framework 4.7.1/4.7.2, Microsoft .NET Framework 4.7.2, Microsoft .NET Framework 2.0.
References:
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8421
http://www.securityfocus.com/bid/105222http://www.securitytracker.com/id/1041636https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8421http://www.securityfocus.com/bid/105222http://www.securitytracker.com/id/1041636https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8421
2018-09-13
Published