CVE-2018-8174
CVE-2018-8174 is a high-severity vulnerability in Microsoft Windows 10 1607 with a CVSS 3.x base score of 7.5. It is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, confirming it has been exploited in the wild (added 2022-02-15). The underlying weakness is classified as CWE-787.
Key facts
- Severity: High (CVSS 3.x base score 7.5)
- CVSS v2: 7.6
- EPSS exploit prediction: 89% (100th percentile)
- Actively exploited: Yes — listed in CISA KEV (added 2022-02-15)
- EU (EUVD) id: EUVD-2018-19844
- EU exploitation: Flagged exploited in the ENISA EU Vulnerability Database (since 2022-02-15)
- Weakness: CWE-787
- Affected product: Microsoft Windows 10 1607
- Published:
- Last modified:
Description
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
Frequently asked questions
- What is CVE-2018-8174?
- A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
- How severe is CVE-2018-8174?
- CVE-2018-8174 has a CVSS 3.x base score of 7.5, rated high severity. It is exploitable over network with high attack complexity, requires no privileges and user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2018-8174 being actively exploited?
- Yes. CVE-2018-8174 is on CISA's Known Exploited Vulnerabilities (KEV) catalog, added on 2022-02-15, which means active exploitation has been confirmed. It should be prioritised for remediation.
- What products are affected by CVE-2018-8174?
- CVE-2018-8174 primarily affects Microsoft Windows 10 1607. In total, 13 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2018-8174?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Because this CVE is known to be actively exploited, treat remediation as urgent — CISA KEV typically sets a short remediation deadline.
- Does CVE-2018-8174 have an EU (EUVD) identifier?
- Yes. CVE-2018-8174 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2018-19844. It is also flagged as exploited in the EUVD (since 2022-02-15).
- When was CVE-2018-8174 published?
- CVE-2018-8174 was published on 2018-05-09 and last updated on 2026-08-13.
References
- http://www.securityfocus.com/bid/103998
- https://blog.0patch.com/2018/05/a-single-instruction-micropatch-for.html
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8174
- https://www.exploit-db.com/exploits/44741/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-8174
Affected products (13)
- cpe:2.3:o:microsoft:windows_10_1607:-:*:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_10_1703:-:*:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_10_1709:-:*:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_10_1803:-:*:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:itanium:*
- cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*
- cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:*
More vulnerabilities in Microsoft Windows 10 1607
- CVE-2026-57092 — Critical (CVSS 9.9): Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network.
- CVE-2026-65791 — Critical (CVSS 9.8): Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a…
- CVE-2026-62893 — Critical (CVSS 9.8): Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.
- CVE-2026-62878 — Critical (CVSS 9.8): Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network.
- CVE-2026-56190 — Critical (CVSS 9.8): Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network.
- CVE-2026-56188 — Critical (CVSS 9.8): Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Network…
All CVEs affecting Microsoft Windows 10 1607 →
Other CWE-787 (Out-of-bounds Write) vulnerabilities
- CVE-2026-42369 — Critical (CVSS 10.0): GV-VMS V20 is a Video Monitoring Software used to gather the feeds of many surveillance cameras and manage other…
- CVE-2026-4746 — Critical (CVSS 10.0): Out-of-bounds Write vulnerability in timeplus-io proton (base/poco/Foundation/src modules). This vulnerability is…
- CVE-2025-43300 — Critical (CVSS 10.0): An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS…
- CVE-2025-24201 — Critical (CVSS 10.0): An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in…
- CVE-2024-42479 — Critical (CVSS 10.0): llama.cpp provides LLM inference in C/C++. The unsafe `data` pointer member in the `rpc_tensor` structure can cause…
- CVE-2024-39791 — Critical (CVSS 10.0): Stack-based buffer overflow vulnerabilities affecting Vonets industrial wifi bridge relays and wifi bridge…