VulnerabilityModified
CVE-2018-8464
An remote code execution vulnerability exists when Microsoft Edge PDF Reader improperly handles objects in memory, aka "Microsoft Edge PDF Remote Code Execution Vulnerability." This affects Microsoft Edge.
HIGH 7.5EPSS 42.6%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 42.6%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
An remote code execution vulnerability exists when Microsoft Edge PDF Reader improperly handles objects in memory, aka "Microsoft Edge PDF Remote Code Execution Vulnerability." This affects Microsoft Edge.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 42.58% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- microsoft/edge
- Source
- secure@microsoft.com
References
- http://www.securityfocus.com/bid/105265Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041623Third Party Advisory, VDB Entry
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8464Patch, Vendor Advisory
- https://research.checkpoint.com/2018/50-adobe-cves-in-50-days/
- http://www.securityfocus.com/bid/105265Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041623Third Party Advisory, VDB Entry
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8464Patch, Vendor Advisory
- https://research.checkpoint.com/2018/50-adobe-cves-in-50-days/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.