CVE-2018-0824CISA KEVEPSS p99.4%

CVE-2018-0824Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability

Microsoft / Windows

Description

Microsoft COM for Windows contains a deserialization of untrusted data vulnerability that allows for privilege escalation and remote code execution via a specially crafted file or script.

Scoring

EPSS73.47% probability of exploitation · percentile 99.4% · 2026-06-18T12:00:27Z

CISA KEV entry

Added to KEV: 2024-08-05

(incoming)1

TypeTargetConfidenceTier
KEVEntryMicrosoft COM for Windows Deserialization of Untrusted Data Vulnerabilitykev-cve-2018-08240%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
Microsoft Windows Privilege Escalation Vulnerability
CVE
CVE-2026-32162
CVE
Microsoft SharePoint Deserialization Vulnerability
CVE
CVE-2025-47994
CVE
Microsoft Windows Server Update Service (WSUS) Deserialization of Untrusted Data Vulnerability
CVE
Microsoft MSCOMCTL.OCX Remote Code Execution Vulnerability
Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.