First published: Thu Apr 12 2018(Updated: )
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Internet Explorer 9, Windows RT 8.1, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Internet Explorer | =9 | |
Microsoft Windows Server | =sp2 | |
Windows 10 | ||
Windows 10 | =1511 | |
Windows 10 | =1607 | |
Windows 10 | =1703 | |
Windows 10 | =1709 | |
Microsoft Windows 7 | =sp1 | |
Microsoft Windows | ||
Microsoft Windows RT | ||
Microsoft Windows Server | =r2-sp1 | |
Microsoft Windows Server | ||
Microsoft Windows Server | =r2 | |
Microsoft Windows Server 2016 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1004 has been classified as critical due to the potential for remote code execution.
To fix CVE-2018-1004, it is recommended to apply the latest security updates provided by Microsoft for affected operating systems.
CVE-2018-1004 affects Windows 7, Windows Server 2012 R2, Internet Explorer 9, Windows 8.1, Windows RT 8.1, among other versions.
Yes, CVE-2018-1004 can be exploited remotely, allowing an attacker to execute arbitrary code on the affected system.
While there is no official workaround for CVE-2018-1004, disabling VBScript in Internet Explorer may reduce the risk of exploitation.