CVE-2018-8174Active Exploitation(microsoft / windows_10_1607)

MEDIUMCVSS 7.5 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for microsoft windows_10_1607 systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.

4.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-08-15. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-787

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1607
  • windows_10_1703
  • windows_10_1709
  • windows_10_1803

Threat summary

  • Active exploitation appears in 1 classified signals
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
windows_10_1607windows_10_1703windows_10_1709windows_10_1803windows_7windows_8.1windows_rt_8.1windows_server_2008windows_server_2012windows_server_2016

2 versions affected across 10 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-17: 1Active Exploitation · 2026-04-17: 1Technical Details · 2026-04-17: 104-17
Signal classification1 categories
Active Exploitation
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • CTIWatch@ctiwatchcloud
    Active Exploitation

    🚨 [HIGH] Active exploitation detected: CVE-2018-8174 Exploit in the wild confirmed for CVE-2018-8174 (CVSS null). A remote code execution vulnerability exists in the way that the VBScript engine handles ... 🔗 http://ctiwatch.cloud/alerts #ZeroDay #ExploitInWild #CyberSecurity

    Post summary

    The alert declares that CVE‑2018‑8174, a remote code execution flaw in the VBScript engine, is actively exploited in the wild, prompting immediate attention from security professionals.

    00010167
    5.6K followersView on X
CPE platform detail13 entries

13 of 13 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1607---
OSmicrosoftwindows_10_1703---
OSmicrosoftwindows_10_1709---
OSmicrosoftwindows_10_1803---
OSmicrosoftwindows_7---
OSmicrosoftwindows_8.1---
OSmicrosoftwindows_rt_8.1---
OSmicrosoftwindows_server_2008---
OSmicrosoftwindows_server_2008r2-itanium
OSmicrosoftwindows_server_2008r2-x64
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016---

Explore more