Vulnerabilities > CVE-2018-8531 - Out-of-bounds Write vulnerability in Microsoft products

047910
CVSS 9.3 - CRITICAL
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
microsoft
CWE-787
critical

Summary

A remote code execution vulnerability exists in the way that Azure IoT Hub Device Client SDK using MQTT protocol accesses objects in memory, aka "Azure IoT Device Client SDK Memory Corruption Vulnerability." This affects Hub Device Client SDK, Azure IoT Edge.

Vulnerable Configurations

Part Description Count
Application
Microsoft
2

Common Weakness Enumeration (CWE)

The Hacker News

idTHN:C3FF55EFF6D358D430A376476FE270D4
last seen2018-10-09
modified2018-10-09
published2018-10-09
reporterThe Hacker News
sourcehttps://thehackernews.com/2018/10/microsoft-windows-update.html
titleMicrosoft October Patch Tuesday Fixes 12 Critical Vulnerabilities