직렬화된 개체를 적절하게 처리하지 못하는 경우 "Windows용 Microsoft COM"에 원격 코드 실행 취약점("Windows용 Microsoft COM 원격 코드 실행 취약점")이 존재합니다. 이는 Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Server에 영향을 미칩니다.
직렬화된 개체를 적절하게 처리하지 못하는 경우 "Windows용 Microsoft COM"에 원격 코드 실행 취약점("Windows용 Microsoft COM 원격 코드 실행 취약점")이 존재합니다. 이는 Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Server에 영향을 미칩니다.
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도 | 88.00 |
| 악용 신호(KEV 등재) | ×1.50 |
| VPI | 100.00 |
VPI 공식 vpi-v1 기준
필수 조치
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
| 소스 | CVSS 버전 | 기본 점수 | 심각도 | 벡터 문자열 | 평가일 |
|---|---|---|---|---|---|
| NVDNIST | 3.1 | 8.8 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | 2026. 04. 20. |
| NVDNIST | 2.0 | 5.1 |
| AV:N/AC:H/Au:N/C:P/I:P/A:P |
| 2026. 04. 20. |