cbcvebase.
CVE-2018-8540
published 2018-12-12

CVE-2018-8540: A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka ".NET Framework Remote Code Injection…

PriorityP268critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
22.13%
97.4th percentile
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka ".NET Framework Remote Code Injection Vulnerability." This affects Microsoft .NET Framework 4.6, Microsoft .NET Framework 3.5, Microsoft .NET Framework 4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.7.1/4.7.2, Microsoft .NET Framework 4.7.2, Microsoft .NET Framework 4.6.2.

Affected

94 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework
microsoftmicrosoft_net_framework

Detection & IOCsextracted from sources · hover to see the quote

  • Exploitation requires passing specific input to an application utilizing susceptible .NET methods — monitor for unusual or malformed input to .NET-based applications, particularly those exposing public endpoints.
  • The vulnerability is in input validation within the Microsoft .NET Framework; focus detection on .NET Framework versions 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2, 4.7, 4.7.1, 4.7.2 — inventory and alert on unpatched instances of these versions.
  • Successful exploitation allows full system takeover including program installation, data manipulation, and new account creation — monitor for unexpected child processes, new local/domain account creation, and privilege escalation events following .NET application activity.
  • ·Exploit status is 'Publicly Disclosed: No; Exploited: No' at time of advisory — no public PoC or in-the-wild exploitation confirmed, reducing immediate urgency but patching remains critical.
  • ·Users with reduced privileges are less impacted, but the vulnerability still allows RCE — do not rely solely on least-privilege as a mitigation.

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_msrc9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.