LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2018-8174: Microsoft Windows VBScript Engine Out-of-Bounds Write Vulnerability

RBRecent Breaches Vulnerability Intelligence·Feb 15, 2022
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Aug 15, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2018-8174 to its Known Exploited Vulnerabilities catalog on Feb 15, 2022, with a federal patch deadline of Aug 15, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution"

CVE-2018-8174 is a remote code execution vulnerability in the Microsoft Windows VBScript engine. It stems from how that engine handles objects in memory and can allow an attacker to run code in the context of the affected user or process. Because the flaw has been tied to ransomware activity, organizations that still run unpatched Windows systems should treat it as a priority for inventory and remediation.

Public detail is limited to the vendor and CISA descriptions; exact affected builds, exploit chains, and scoring must be confirmed against the Microsoft advisory for this CVE. The required action is to apply updates per vendor instructions.

How it works

The weakness is classified as CWE-787 (out-of-bounds write). In broad terms for this class, the VBScript engine mishandles objects in memory so that a write operation can go outside the intended buffer or object bounds. An attacker who can supply crafted input that reaches the engine—commonly via web content, documents, or other script-hosting paths that invoke VBScript—may corrupt memory in a way that leads to arbitrary code execution.

No exploit code or step-by-step mechanics are provided in the available facts. Defenders should assume that successful abuse yields remote code execution under the privileges of the process hosting the engine, which on Windows often means user-level or browser/script-host context unless further elevation occurs. Confirm attack surface and any documented vectors only against the official vendor advisory.

Am I affected? How to find it in your systems

The vulnerability affects Microsoft Windows systems that include the VBScript engine. That component is historically present on client and server Windows installations and can be reached by Internet Explorer, legacy script hosts, Office or other applications that embed or call VBScript, and any custom or third-party software that loads the engine.

How to remediate

Patch first. Apply the Microsoft security updates that address CVE-2018-8174 exactly as specified in the vendor advisory and per CISA’s required action: apply updates per vendor instructions. Use your standard Windows Update, WSUS, SCCM, or Intune deployment process; verify installation with the KB or build numbers published by Microsoft.

If you can't patch immediately

Until the vendor update can be deployed, apply compensating controls that shrink the attack surface and improve detection.

These measures reduce likelihood and impact but do not replace the official patch. Schedule the update as soon as operationally feasible.

If your data may have been exposed

Actively exploited vulnerabilities, including those with known ransomware use, frequently lead to credential theft, lateral movement, and data encryption or exfiltration. If you have evidence of exploitation or ransomware activity on systems that were unpatched for CVE-2018-8174, follow your incident-response plan: isolate affected hosts, preserve forensic images and logs, reset credentials, and assess backup integrity before recovery.

As a further check on whether associated identities appear in known breach datasets, you can run a free exposure scan of your email addresses against aggregated breach records and then force password resets and MFA enrollment where hits are found.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
WeaknessCWE-787
Added to CISA KEVFeb 15, 2022
Federal patch deadlineAug 15, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities