CVE-2018-0824CISA KEV
Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability
CISA lists this Microsoft vulnerability as known exploited. Its MSRC release detail is outside this installation's collected history.
CISA catalog record
Microsoft COM for Windows contains a deserialization of untrusted data vulnerability that allows for privilege escalation and remote code execution via a specially crafted file or script.
- Product
- Windows
- Added to KEV
- 5 Aug 2024
- Federal remediation due
- 26 Aug 2024
- Known ransomware use
- Not reported