CVE-2018-8475
published 2018-09-13CVE-2018-8475: A remote code execution vulnerability exists when Windows does not properly handle specially crafted image files, aka "Windows Remote Code Execution…
PriorityP356high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
14.65%
96.3th percentile
A remote code execution vulnerability exists when Windows does not properly handle specially crafted image files, aka "Windows Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
Affected
51 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10_servers | — | — |
| microsoft | windows_10_servers | — | — |
| microsoft | windows_7 | — | — |
| microsoft | windows_7 | — | — |
| microsoft | windows_8.1 | — | — |
| microsoft | windows_8.1 | — | — |
| microsoft | windows_rt_8.1 | — | — |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2018-8475 is triggered when a user opens or downloads a specially crafted image file; detection should focus on suspicious image file downloads and rendering via Windows Graphics Component. ↗
- →The attack vector requires user interaction — specifically convincing a user to download/view a malicious image file. Monitor for image files delivered via email, web, or Office documents on unpatched Windows systems. ↗
- →CVE-2018-8475 was publicly disclosed prior to patch release (Exploit Status: Publicly Disclosed: Yes), increasing likelihood of exploitation. Prioritize detection on workstation-type devices used for email or internet browsing. ↗
- →The vulnerable component is the Microsoft Graphics Component. Monitor processes associated with image rendering (e.g., Windows Photo Viewer, Explorer thumbnail generation) for anomalous child process spawning on unpatched systems. ↗
- →CVE-2018-8475 affects a broad range of Windows versions. Ensure patch KB4457138 and related KBs are applied; absence of these patches on internet-facing or email-enabled workstations is a high-risk indicator. ↗
- ·CVE-2018-8475 was publicly disclosed before the patch was released but had not been observed exploited in the wild at patch time. Exploitation likelihood is rated 'More Likely' for both latest and older software releases. ↗
- ·The vulnerability resides in Windows image parsing (Microsoft Graphics Component), not a browser engine — meaning it can be triggered outside of browser context, e.g., via Explorer thumbnail rendering or email preview. ↗
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-24jw-cfv8-4gp7: A remote code execution vulnerability exists when Windows does not properly handle specially crafted image files, aka "Windows Remote Code Execution V
ghsa_unreviewed·2022-05-13
CVE-2018-8475 [HIGH] GHSA-24jw-cfv8-4gp7: A remote code execution vulnerability exists when Windows does not properly handle specially crafted image files, aka "Windows Remote Code Execution V
A remote code execution vulnerability exists when Windows does not properly handle specially crafted image files, aka "Windows Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
Microsoft
Windows Remote Code Execution Vulnerability
vendor_msrc·2018-09-11·CVSS 8.8
CVE-2018-8475 [HIGH] Windows Remote Code Execution Vulnerability
Windows Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists when Windows does not properly handle specially crafted image files. An attacker who successfully exploited the vulnerability could execute arbitrary code.
To exploit the vulnerability, an attacker would have to convince a user to download an image file.
The update addresses the vulnerability by properly handling image files.
Microsoft Graphics Component: Microsoft Graphics Component
Issuing CNA: Microsoft
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:Yes;Exploited:No;Latest Software Release:Exploitation More Likely;Older Software Release:Exploitation More Likely;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4457138
Reference: htt
No detection rules found.
No public exploits indexed.
Trendmicro
September Patch Tuesday: Windows Fixes ALPC Bug
blogs_trendmicro·2018-09-12·CVSS 7.8
CVE-2018-8440 [HIGH] September Patch Tuesday: Windows Fixes ALPC Bug
Exploits y vulnerabilidades
## September Patch Tuesday: Windows Fixes ALPC Bug
September’s Patch Tuesday provides a security patch for CVE-2018-8440, an elevation of privilege vulnerability that occurs when Windows incorrectly handles calls to the Advanced Local Procedure Call (ALPC) interface.
By: Trend Micro Sep 12, 2018 Read time: ( words)
Save to Folio
September’s Patch Tuesday provides a security patch for CVE-2018-8440 , an elevation of privilege vulnerability that occurs when Windows incorrectly handles calls to the Advanced Local Procedure Call (ALPC) interface. This bug allows threat actors to run code with administrative privileges, install programs, or even create new accounts with full user rights. This bug’s source code has been publicly disclosed as of August 27 via Twit
Trendmicro
September Patch Tuesday: Windows Fixes ALPC Bug
blogs_trendmicro·2018-09-12·CVSS 7.8
CVE-2018-8440 [HIGH] September Patch Tuesday: Windows Fixes ALPC Bug
Exploits & Vulnerabilities
# September Patch Tuesday: Windows Fixes ALPC Bug
September’s Patch Tuesday provides a security patch for CVE-2018-8440, an elevation of privilege vulnerability that occurs when Windows incorrectly handles calls to the Advanced Local Procedure Call (ALPC) interface.
By: Trend Micro
2018/09/12
Read time: ( words)
Save to Folio
September’s Patch Tuesday provides a security patch for CVE-2018-8440, an elevation of privilege vulnerability that occurs when Windows incorrectly handles calls to the Advanced Local Procedure Call (ALPC) interface. This bug allows threat actors to run code with administrative privileges, install programs, or even create new accounts with full user rights. This bug’s source code has been publicly disclosed as of August 27 via Twitter
Trendmicro
September Patch Tuesday: Windows Fixes ALPC Bug
blogs_trendmicro·2018-09-12·CVSS 7.8
CVE-2018-8440 [HIGH] September Patch Tuesday: Windows Fixes ALPC Bug
Exploits & Vulnerabilities
## September Patch Tuesday: Windows Fixes ALPC Bug
September’s Patch Tuesday provides a security patch for CVE-2018-8440, an elevation of privilege vulnerability that occurs when Windows incorrectly handles calls to the Advanced Local Procedure Call (ALPC) interface.
By: Trend Micro Sep 12, 2018 Read time: ( words)
Save to Folio
September’s Patch Tuesday provides a security patch for CVE-2018-8440 , an elevation of privilege vulnerability that occurs when Windows incorrectly handles calls to the Advanced Local Procedure Call (ALPC) interface. This bug allows threat actors to run code with administrative privileges, install programs, or even create new accounts with full user rights. This bug’s source code has been publicly disclosed as of August 27 via Twitt
Trendmicro
September Patch Tuesday: Windows Fixes ALPC Bug
blogs_trendmicro·2018-09-12·CVSS 7.8
CVE-2018-8440 [HIGH] September Patch Tuesday: Windows Fixes ALPC Bug
Exploits & Vulnerabilities
## September Patch Tuesday: Windows Fixes ALPC Bug
September’s Patch Tuesday provides a security patch for CVE-2018-8440, an elevation of privilege vulnerability that occurs when Windows incorrectly handles calls to the Advanced Local Procedure Call (ALPC) interface.
By: Trend Micro 2018/09/12 Read time: ( words)
Save to Folio
September’s Patch Tuesday provides a security patch for CVE-2018-8440 , an elevation of privilege vulnerability that occurs when Windows incorrectly handles calls to the Advanced Local Procedure Call (ALPC) interface. This bug allows threat actors to run code with administrative privileges, install programs, or even create new accounts with full user rights. This bug’s source code has been publicly disclosed as of August 27 via Twitter
Trendmicro
September Patch Tuesday: Windows Fixes ALPC Bug
blogs_trendmicro·2018-09-12·CVSS 7.8
CVE-2018-8440 [HIGH] September Patch Tuesday: Windows Fixes ALPC Bug
Ausnutzung von Schwachstellen
## September Patch Tuesday: Windows Fixes ALPC Bug
September’s Patch Tuesday provides a security patch for CVE-2018-8440, an elevation of privilege vulnerability that occurs when Windows incorrectly handles calls to the Advanced Local Procedure Call (ALPC) interface.
By: Trend Micro Sep 12, 2018 Read time: ( words)
Save to Folio
September’s Patch Tuesday provides a security patch for CVE-2018-8440 , an elevation of privilege vulnerability that occurs when Windows incorrectly handles calls to the Advanced Local Procedure Call (ALPC) interface. This bug allows threat actors to run code with administrative privileges, install programs, or even create new accounts with full user rights. This bug’s source code has been publicly disclosed as of August 27 via Tw
Talos
Microsoft Patch Tuesday - September 2018
blogs_talos·2018-09-11·CVSS 8.4
[HIGH] Microsoft Patch Tuesday - September 2018
Microsoft released its monthly set of security updates today for a variety of its products that address a variety of bugs. The latest Patch Tuesday covers 61 vulnerabilities, 17 of which are rated "critical," 43 that are rated "important" and one that is considered to have "moderate" severity.
The advisories cover bugs in the Internet Explorer web browser, Jet Database Engine and the Chakra scripting engine, among other products and software.
This update also includes two critical advisories, one of which covers security updates to Adobe Flash, and another that deals with a denial-of-service vulnerability in the Microsoft Windows operating system.
## Critical vulnerabilitiesMicrosoft released coverage for 17 critical bugs. Cisco Talos believes 16 of these are of special importance and n
Qualys
September 2018 Patch Tuesday – 61 Vulns, FragmentSmack, Hyper-V Escape
blogs_qualys·2018-09-11·CVSS 7.5
CVE-2018-8475 [HIGH] September 2018 Patch Tuesday – 61 Vulns, FragmentSmack, Hyper-V Escape
In this month’s Patch Tuesday release there are 61 vulnerabilities patched with 17 Criticals. Out of the criticals, most are browser-related, with the rest including Windows, Hyper-V, and .net Framework. A vulnerability ( CVE-2018-8475 ) in Windows’ image parsing has been publicly disclosed, in addition to a vulnerability ( CVE-2018-8457 ) in the Scripting Engine.
## Workstation Patches
Browser and Scripting Engine patches should be prioritized for workstation-type devices, meaning any system that is used for email or to access the internet via a browser. The PDF viewer, Windows image parsing, .net Framework, and Windows font library also have patches available that require a user to interact with a malicious site or file. With two of these vulnerabilities being publicly disclosed, it is
Krebs
Patch Tuesday, September 2018 Edition
blogs_krebs·2018-09-11·CVSS 7.5
[HIGH] Patch Tuesday, September 2018 Edition
Adobe and Microsoft today each released patches to fix serious security holes in their software. Adobe pushed out a new version of its beleaguered Flash Player browser plugin. Redmond issued updates to address at least 61 distinct vulnerabilities in Microsoft Windows and related programs, including several flaws that were publicly detailed prior to today and one “zero-day” bug in Windows that is already being actively exploited by attackers.
As per usual, the bulk of the fixes from Microsoft tackle security weaknesses in the company’s Web browsers, Internet Explorer and Edge . Patches also are available for Windows, Office , Sharepoint , and the .NET Framework , among other components.
Of the 61 bugs fixed in this patch batch, 17 earned Microsoft’s “critical” rating, meaning malware or m
Krebs
Patch Tuesday, September 2018 Edition
blogs_krebs·2018-09-11·CVSS 7.5
[HIGH] Patch Tuesday, September 2018 Edition
Adobe and Microsoft today each released patches to fix serious security holes in their software. Adobe pushed out a new version of its beleaguered Flash Player browser plugin. Redmond issued updates to address at least 61 distinct vulnerabilities in Microsoft Windows and related programs, including several flaws that were publicly detailed prior to today and one “zero-day” bug in Windows that is already being actively exploited by attackers.
Of the 61 bugs fixed in this patch batch, 17 earned Microsoft’s “critical” rating, meaning malware or miscreants could use them to break into Windows computers with little or no help from users.
The zero-day flaw, CVE-2018-8440, affects Microsoft operating systems from Windows 7 through Windows 10 and allows a program launched by a restricted Windows
Talos
Microsoft Patch Tuesday - September 2018
blogs_talos·2018-09-11·CVSS 8.4
[HIGH] Microsoft Patch Tuesday - September 2018
## Microsoft Patch Tuesday - September 2018
Microsoft released its monthly set of security updates today for a variety of its products that address a variety of bugs. The latest Patch Tuesday covers 61 vulnerabilities, 17 of which are rated "critical," 43 that are rated "important" and one that is considered to have "moderate" severity.
The advisories cover bugs in the Internet Explorer web browser, Jet Database Engine and the Chakra scripting engine, among other products and software.
This update also includes two critical advisories, one of which covers security updates to Adobe Flash, and another that deals with a denial-of-service vulnerability in the Microsoft Windows operating system.
## Critical vulnerabilities Microsoft released coverage for 17 critical bugs. Cisco Talos believ
Qualys
Sept 2018 Patch Tuesday | Qualys
blogs_qualys·2018-09-11·CVSS 7.5
CVE-2018-8475 [HIGH] Sept 2018 Patch Tuesday | Qualys
In this month’s Patch Tuesday release there are 61 vulnerabilities patched with 17 Criticals. Out of the criticals, most are browser-related, with the rest including Windows, Hyper-V, and .net Framework. A vulnerability (CVE-2018-8475) in Windows’ image parsing has been publicly disclosed, in addition to a vulnerability (CVE-2018-8457) in the Scripting Engine.
### Workstation Patches
Browser and Scripting Engine patches should be prioritized for workstation-type devices, meaning any system that is used for email or to access the internet via a browser. The PDF viewer, Windows image parsing, .net Framework, and Windows font library also have patches available that require a user to interact with a malicious site or file. With two of these vulnerabilities being publicly disclosed, it is im
http://www.securityfocus.com/bid/105277http://www.securitytracker.com/id/1041626https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8475http://www.securityfocus.com/bid/105277http://www.securitytracker.com/id/1041626https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8475
2018-09-13
Published