cbcvebase.
CVE-2018-8450
published 2018-11-14

CVE-2018-8450: A remote code execution vulnerability exists when Windows Search handles objects in memory, aka "Windows Search Remote Code Execution Vulnerability." This…

PriorityP260high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
16.08%
96.5th percentile
A remote code execution vulnerability exists when Windows Search handles objects in memory, aka "Windows Search Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.

Affected

46 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10_servers
microsoftwindows_10_servers
microsoftwindows_7
microsoftwindows_7
microsoftwindows_8.1
microsoftwindows_8.1
microsoftwindows_rt_8.1
microsoftwindows_server_2008
microsoftwindows_server_2008
microsoftwindows_server_2008
microsoftwindows_server_2008
microsoftwindows_server_2008
microsoftwindows_server_2008_r2

Detection & IOCsextracted from sources · hover to see the quote

  • Exploit vector involves specially crafted messages sent to the Windows Search service; monitor for anomalous or malformed inbound requests to the Windows Search service process.
  • In enterprise environments, exploitation can be triggered remotely over SMB by an authenticated attacker; monitor for unusual SMB connections targeting hosts running Windows Search, particularly from unexpected authenticated sources.
  • ·Exploitation is rated 'More Likely' for both latest and older software releases per Microsoft's exploitability index, meaning detection and patching should be prioritized even though no in-the-wild exploitation was confirmed at time of disclosure.
  • ·The vulnerability affects a wide range of Windows versions; ensure detection coverage spans all affected platforms: Windows 7, Windows 8.1, Windows RT 8.1, Windows 10, Windows Server 2008/2008 R2, Windows Server 2012/2012 R2, and Windows Server 2016.

CVSS provenance

nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_msrc7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.