Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2018-0772

EPSS 32.05% · P97
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2018-0772

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Internet Explorer and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2018-0758, CVE-2018-0762, CVE-2018-0768, CVE-2018-0769, CVE-2018-0770, CVE-2018-0773, CVE-2018-0774, CVE-2018-0775, CVE-2018-0776, CVE-2018-0777, CVE-2018-0778, and CVE-2018-0781.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Microsoft Windows Edge和Internet Explorer scripting引擎缓冲区错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Microsoft Windows 7 SP1等都是美国微软(Microsoft)公司发布的一系列操作系统。Microsoft Edge和Internet Explorer(IE)都是Windows系统附带的Web浏览器。前者是最新操作系统Windows 10附带的默认浏览器,后者是Windows 10之前操作系统附带的默认浏览器。scripting engine是其中的一个JavaScript引擎组件。 Microsoft Windows中的IE 9、10、11和Edge的scripting引擎存在远程
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
Microsoft CorporationMicrosoft Edge, Internet Explorer Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016. -

II. Public POCs for CVE-2018-0772

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2018-0772

登录查看更多情报信息。

Same Patch Batch · Microsoft Corporation · 2018-01-04 · 32 CVEs total

CVE-2018-0766Microsoft Windows Edge 信息泄露漏洞
CVE-2018-0803Microsoft Windows Edge 权限许可和访问控制问题漏洞
CVE-2018-0800Microsoft Windows Edge scripting引擎信息泄露漏洞
CVE-2018-0788Microsoft Windows Adobe Type Manager Font Driver (Atmfd.dll) 权限许可和访问控制问题漏洞
CVE-2018-0781Microsoft Windows Edge scripting引擎缓冲区错误漏洞
CVE-2018-0780Microsoft Windows Edge scripting引擎信息泄露漏洞
CVE-2018-0778Microsoft Windows Edge scripting引擎缓冲区错误漏洞
CVE-2018-0777Microsoft Windows Edge scripting引擎缓冲区错误漏洞
CVE-2018-0776Microsoft Windows Edge scripting引擎缓冲区错误漏洞
CVE-2018-0775Microsoft Windows Edge scripting引擎缓冲区错误漏洞
CVE-2018-0774Microsoft Windows Edge scripting引擎缓冲区错误漏洞
CVE-2018-0773Microsoft Windows Edge scripting引擎缓冲区错误漏洞
CVE-2018-0770Microsoft Windows Edge的scripting引擎缓冲区错误漏洞
CVE-2018-0769Microsoft Windows Edge scripting引擎缓冲区错误漏洞
CVE-2018-0768Microsoft Windows Edge scripting引擎缓冲区错误漏洞
CVE-2018-0767Microsoft Windows Edge scripting引擎信息泄露漏洞
CVE-2018-0741Microsoft Windows Color Management Module (Icm32.dll) 信息泄露漏洞
CVE-2018-0762Microsoft Windows ge和Internet Explorer scripting引擎缓冲区错误漏洞
CVE-2018-0758Microsoft Windows Edge scripting引擎缓冲区错误漏洞
CVE-2018-0754Microsoft Windows Adobe Type Manager Font Driver (Atmfd.dll) 信息泄露漏洞

Showing top 20 of 32 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2018-0772

No comments yet


Leave a comment