cbcvebase.
CVE-2018-8423
published 2018-10-10

CVE-2018-8423: A remote code execution vulnerability exists in the Microsoft JET Database Engine, aka "Microsoft JET Database Engine Remote Code Execution Vulnerability."…

PriorityP350high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
32.70%
98.2th percentile
A remote code execution vulnerability exists in the Microsoft JET Database Engine, aka "Microsoft JET Database Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.

Affected

56 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10_servers
microsoftwindows_10_servers
microsoftwindows_7
microsoftwindows_7
microsoftwindows_8.1
microsoftwindows_8.1
microsoftwindows_rt_8.1
microsoftwindows_server_2008

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2018-8423 is triggered when a user opens or imports a specially crafted Microsoft JET Database Engine file; monitor for suspicious JET/MDB file opens, especially via email attachments or Office documents.
  • The vulnerability requires a user to open or import a specially crafted JET Database Engine file; in email attack scenarios, the attacker sends the crafted file and convinces the user to open it — flag inbound email attachments with JET/MDB/ACCDB extensions.
  • ·Exploit status is publicly disclosed but not confirmed exploited in the wild at time of advisory; exploitation assessed as 'Less Likely' for both latest and older software releases.
  • ·The October 2018 patch may be incomplete; customers should restrict interaction with vulnerable applications to trusted files until full remediation is confirmed.

CVSS provenance

nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_msrc7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.