CVE-2018-8552
published 2018-11-14CVE-2018-8552: An information disclosure vulnerability exists when VBScript improperly discloses the contents of its memory, which could provide an attacker with information…
PriorityP264high7.5CVSS 3.0
AVNACHPRNUIRSUCHIHAH
EXPLOIT
EPSS
50.96%
98.8th percentile
An information disclosure vulnerability exists when VBScript improperly discloses the contents of its memory, which could provide an attacker with information to further compromise the user's computer or data, aka "Windows Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10.
Affected
33 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer_10 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Crash/OOB read occurs inside vbscript!rtFilter when a VBScript array containing a class object with a Default Property that calls ReDim is passed to the Filter() function — look for VBScript executing Filter() on arrays containing class instances with Default Property accessors that resize arrays. ↗
- →The fault manifests as an access violation in OLEAUT32!VariantCopy called from vbscript!rtFilter+0x183, reading from an unmapped/invalid memory page — crash signature: OLEAUT32!VariantCopy+0xb with esi pointing to an invalid address (e.g. 0d9cf000). ↗
- →The exploit uses 'On Error Resume Next' to suppress errors and keep execution going after the OOB read — VBScript with this directive combined with Filter() calls on heterogeneous arrays (mixing strings and class objects) should be treated as suspicious. ↗
- →Exploitation vector is a web-based attack via Internet Explorer (IE 9/10/11) or an ActiveX control marked 'safe for initialization' embedded in an Office document hosting the IE rendering engine — monitor for iexplore.exe spawning child processes or unusual memory reads from vbscript.dll. ↗
- ·The exploit PoC uses 'On Error Resume Next' which suppresses the crash in-process; in a weaponized exploit the OOB read would be leveraged for information disclosure to bypass ASLR/DEP rather than causing an immediate visible crash — detection based solely on crash telemetry may miss exploitation. ↗
- ·The vulnerability is an out-of-bounds read (information disclosure) in vbscript!rtFilter, not a direct write primitive — exploitation requires chaining with additional techniques to achieve code execution. ↗
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.07.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
vendor_msrc6.4MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Scripting Engine Memory Corruption Vulnerability
vendor_msrc·2018-11-13·CVSS 6.4
CVE-2018-8552 [HIGH] Scripting Engine Memory Corruption Vulnerability
Scripting Engine Memory Corruption Vulnerability
Description: A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
In a web-based attack scenario, an attacker could host a specially crafted websi
GHSA
GHSA-5f59-wq77-4wm6: An information disclosure vulnerability exists when VBScript improperly discloses the contents of its memory, which could provide an attacker with inf
ghsa_unreviewed·2022-05-13
CVE-2018-8552 [HIGH] CWE-119 GHSA-5f59-wq77-4wm6: An information disclosure vulnerability exists when VBScript improperly discloses the contents of its memory, which could provide an attacker with inf
An information disclosure vulnerability exists when VBScript improperly discloses the contents of its memory, which could provide an attacker with information to further compromise the user's computer or data, aka "Windows Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10.
No detection rules found.
Trendmicro
Patch Tuesday Fixes Zero-Day Win32k Bug
blogs_trendmicro·2018-11-14·CVSS 7.8
CVE-2018-8589 [HIGH] Patch Tuesday Fixes Zero-Day Win32k Bug
Exploits & Vulnerabilities
# Patch Tuesday Fixes Zero-Day Win32k Bug
This month’s round of updates, which fixes 63 bugs, includes a patch for a zero-day vulnerability (CVE-2018-8589) that is already being used in malicious attacks.
By: Trend Micro
2018/11/14
Read time: ( words)
Save to Folio
As the year comes to a close, updates for both Microsoft and Adobe products and services are still ongoing via Patch Tuesday. This month’s round of updates, which fixes 63 bugs, includes a patch for a zero-day vulnerability that is already being used in malicious attacks. Perhaps the most notable vulnerability addressed this month is CVE-2018-8589, another Win32k Elevation of Privilege Vulnerability that is similar to October’s CVE-2018-8453, which allows an attacker to make use of specially craf
Trendmicro
Patch Tuesday Fixes Zero-Day Win32k Bug
blogs_trendmicro·2018-11-14·CVSS 7.8
CVE-2018-8589 [HIGH] Patch Tuesday Fixes Zero-Day Win32k Bug
Exploits y vulnerabilidades
## Patch Tuesday Fixes Zero-Day Win32k Bug
This month’s round of updates, which fixes 63 bugs, includes a patch for a zero-day vulnerability (CVE-2018-8589) that is already being used in malicious attacks.
By: Trend Micro Nov 14, 2018 Read time: ( words)
Save to Folio
As the year comes to a close, updates for both Microsoft and Adobe products and services are still ongoing via Patch Tuesday . This month’s round of updates, which fixes 63 bugs, includes a patch for a zero-day vulnerability that is already being used in malicious attacks. Perhaps the most notable vulnerability addressed this month is CVE-2018-8589 , another Win32k Elevation of Privilege Vulnerability that is similar to October ’s CVE-2018-8453 , which allows an attacker to make use of special
Trendmicro
Patch Tuesday Fixes Zero-Day Win32k Bug
blogs_trendmicro·2018-11-14·CVSS 7.8
CVE-2018-8589 [HIGH] Patch Tuesday Fixes Zero-Day Win32k Bug
Ausnutzung von Schwachstellen
## Patch Tuesday Fixes Zero-Day Win32k Bug
This month’s round of updates, which fixes 63 bugs, includes a patch for a zero-day vulnerability (CVE-2018-8589) that is already being used in malicious attacks.
By: Trend Micro Nov 14, 2018 Read time: ( words)
Save to Folio
As the year comes to a close, updates for both Microsoft and Adobe products and services are still ongoing via Patch Tuesday . This month’s round of updates, which fixes 63 bugs, includes a patch for a zero-day vulnerability that is already being used in malicious attacks. Perhaps the most notable vulnerability addressed this month is CVE-2018-8589 , another Win32k Elevation of Privilege Vulnerability that is similar to October ’s CVE-2018-8453 , which allows an attacker to make use of speci
Trendmicro
Patch Tuesday Fixes Zero-Day Win32k Bug
blogs_trendmicro·2018-11-14·CVSS 7.8
CVE-2018-8589 [HIGH] Patch Tuesday Fixes Zero-Day Win32k Bug
Sfruttamento vulnerabilità
## Patch Tuesday Fixes Zero-Day Win32k Bug
This month’s round of updates, which fixes 63 bugs, includes a patch for a zero-day vulnerability (CVE-2018-8589) that is already being used in malicious attacks.
By: Trend Micro Nov 14, 2018 Read time: ( words)
Save to Folio
As the year comes to a close, updates for both Microsoft and Adobe products and services are still ongoing via Patch Tuesday . This month’s round of updates, which fixes 63 bugs, includes a patch for a zero-day vulnerability that is already being used in malicious attacks. Perhaps the most notable vulnerability addressed this month is CVE-2018-8589 , another Win32k Elevation of Privilege Vulnerability that is similar to October ’s CVE-2018-8453 , which allows an attacker to make use of speciall
Trendmicro
Patch Tuesday Fixes Zero-Day Win32k Bug
blogs_trendmicro·2018-11-14·CVSS 7.8
CVE-2018-8589 [HIGH] Patch Tuesday Fixes Zero-Day Win32k Bug
Exploits & Vulnerabilities
## Patch Tuesday Fixes Zero-Day Win32k Bug
This month’s round of updates, which fixes 63 bugs, includes a patch for a zero-day vulnerability (CVE-2018-8589) that is already being used in malicious attacks.
By: Trend Micro Nov 14, 2018 Read time: ( words)
Save to Folio
As the year comes to a close, updates for both Microsoft and Adobe products and services are still ongoing via Patch Tuesday . This month’s round of updates, which fixes 63 bugs, includes a patch for a zero-day vulnerability that is already being used in malicious attacks. Perhaps the most notable vulnerability addressed this month is CVE-2018-8589 , another Win32k Elevation of Privilege Vulnerability that is similar to October ’s CVE-2018-8453 , which allows an attacker to make use of speciall
Trendmicro
Patch Tuesday Fixes Zero-Day Win32k Bug
blogs_trendmicro·2018-11-14·CVSS 7.8
CVE-2018-8589 [HIGH] Patch Tuesday Fixes Zero-Day Win32k Bug
Exploits & Vulnerabilities
## Patch Tuesday Fixes Zero-Day Win32k Bug
This month’s round of updates, which fixes 63 bugs, includes a patch for a zero-day vulnerability (CVE-2018-8589) that is already being used in malicious attacks.
By: Trend Micro 2018/11/14 Read time: ( words)
Save to Folio
As the year comes to a close, updates for both Microsoft and Adobe products and services are still ongoing via Patch Tuesday . This month’s round of updates, which fixes 63 bugs, includes a patch for a zero-day vulnerability that is already being used in malicious attacks. Perhaps the most notable vulnerability addressed this month is CVE-2018-8589 , another Win32k Elevation of Privilege Vulnerability that is similar to October ’s CVE-2018-8453 , which allows an attacker to make use of specially
http://www.securityfocus.com/bid/105786https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8552https://www.exploit-db.com/exploits/45924/http://www.securityfocus.com/bid/105786https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8552https://www.exploit-db.com/exploits/45924/
2018-11-14
Published