CVE-2018-7891: Milestonesys Xprotect

High severity, CVSS 8.1. EPSS: 4% chance of exploitation in the next 30 days.

The Milestone XProtect Video Management Software (Corporate, Expert, Professional+, Express+, Essential+) 2016 R1 (10.0.a) to 2018 R1 (12.1a) contains .NET Remoting endpoints that are vulnerable to deserialization attacks resulting in remote code execution.

Affected products

  • Milestonesys Xprotect: from 10.0.a, up to and including 12.1a
  • Siemens Siveillance Vms: before 10.0a (fixed in 10.0a); before 10.1a (fixed in 10.1a); before 10.2b (fixed in 10.2b); before 11.1a (fixed in 11.1a); before 11.2a (fixed in 11.2a); before 12.1a (fixed in 12.1a)

Published 2018-04-30. Last modified 2026-06-17.