cvedb.io
CVE-2018-1004
HIGH · CVSS 8.8
EPSS exploitation probability: 0%
Published 2018-04-12T01:29:09.173 · Last modified 2026-06-17T01:50:16.430

Summary

A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Internet Explorer 9, Windows RT 8.1, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10.

Affected products

microsoft — internet_explorer

Does this affect you?

Add your gear to cvedb and we'll alert you only when microsoft ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.