3 mins read
Double Kill Exploit Jumps from Office to Explorer

Copyright 2023, IT Voice Media Pvt. Ltd.
All Rights Reserved

This month, Microsoft released a patch for the zero-day vulnerability (CVE-2018-8174) — central to the Double Kill exploit — affecting VBScript Engine. In this coordinated release, Qihoo 360 researchers discovered that it was exploited in the wild as early as April 18, 2018, allowing code execution by remote attackers. The vulnerability was used to install a backdoor probably used for cyber-espionage. This is considered the highest priority update among those issued in May.