cbcvebase.
CVE-2018-8475
published 2018-09-13

CVE-2018-8475: A remote code execution vulnerability exists when Windows does not properly handle specially crafted image files, aka "Windows Remote Code Execution…

PriorityP356high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
14.65%
96.3th percentile
A remote code execution vulnerability exists when Windows does not properly handle specially crafted image files, aka "Windows Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.

Affected

51 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10_servers
microsoftwindows_10_servers
microsoftwindows_7
microsoftwindows_7
microsoftwindows_8.1
microsoftwindows_8.1
microsoftwindows_rt_8.1
microsoftwindows_server_2008
microsoftwindows_server_2008
microsoftwindows_server_2008
microsoftwindows_server_2008

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2018-8475 is triggered when a user opens or downloads a specially crafted image file; detection should focus on suspicious image file downloads and rendering via Windows Graphics Component.
  • The attack vector requires user interaction — specifically convincing a user to download/view a malicious image file. Monitor for image files delivered via email, web, or Office documents on unpatched Windows systems.
  • CVE-2018-8475 was publicly disclosed prior to patch release (Exploit Status: Publicly Disclosed: Yes), increasing likelihood of exploitation. Prioritize detection on workstation-type devices used for email or internet browsing.
  • The vulnerable component is the Microsoft Graphics Component. Monitor processes associated with image rendering (e.g., Windows Photo Viewer, Explorer thumbnail generation) for anomalous child process spawning on unpatched systems.
  • CVE-2018-8475 affects a broad range of Windows versions. Ensure patch KB4457138 and related KBs are applied; absence of these patches on internet-facing or email-enabled workstations is a high-risk indicator.
  • ·CVE-2018-8475 was publicly disclosed before the patch was released but had not been observed exploited in the wild at patch time. Exploitation likelihood is rated 'More Likely' for both latest and older software releases.
  • ·The vulnerability resides in Windows image parsing (Microsoft Graphics Component), not a browser engine — meaning it can be triggered outside of browser context, e.g., via Explorer thumbnail rendering or email preview.

CVSS provenance

nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.