LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2018-0824: Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability

RBRecent Breaches Vulnerability Intelligence·Aug 5, 2024
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Aug 26, 2024
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2018-0824 to its Known Exploited Vulnerabilities catalog on Aug 5, 2024, with a federal patch deadline of Aug 26, 2024 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft COM for Windows contains a deserialization of untrusted data vulnerability that allows for privilege escalation and remote code execution via a specially crafted file or script.

CVE-2018-0824 is a deserialization of untrusted data vulnerability in Microsoft COM for Windows. Per the CISA summary, it allows privilege escalation and remote code execution via a specially crafted file or script.

COM is a foundational Windows component, so this class of flaw can put systems at risk of full compromise if untrusted input reaches the vulnerable path. Confirm exact impact, affected configurations, and fixes against the vendor advisory.

How it works

The weakness is CWE-502: Deserialization of Untrusted Data. In this class of flaw, software accepts serialized objects or data streams from an untrusted source and reconstructs them without adequate validation or type restrictions. An attacker who can supply the data can embed objects that, when deserialized, trigger unintended method calls, object construction, or code execution in the context of the process performing the deserialization.

For this Microsoft COM vulnerability, the CISA summary states that a specially crafted file or script is used to reach the vulnerable deserialization logic, resulting in privilege escalation and remote code execution. No further exploit mechanics are provided here; defenders should treat any untrusted file or script interaction with COM as a potential vector and obtain precise details from the vendor advisory.

Am I affected? How to find it in your systems

The vulnerability affects Microsoft Windows systems that use COM. COM is present by default on most Windows installations and is commonly invoked by applications, scripts, services, and administrative tools.

How to remediate

Patch first. Apply the vendor-supplied update for CVE-2018-0824 as described in the Microsoft advisory. CISA’s required action is to apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

If you can't patch immediately

Use compensating controls to lower the likelihood and impact of exploitation until the vendor update can be applied.

If your data may have been exposed

Actively exploited vulnerabilities of this type can lead to system compromise and subsequent data exposure. Ransomware use is not documented for this CVE. If you suspect exploitation, isolate affected hosts, preserve forensic evidence, and follow your incident-response process. You can also run a free exposure scan of your email address to check whether it appears in known breach data sets.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
WeaknessCWE-502
Added to CISA KEVAug 5, 2024
Federal patch deadlineAug 26, 2024
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities