Remote code execution in Microsoft Publisher

Published: 2018-06-12 21:51:43
Severity High
Patch available YES
Number of vulnerabilities 1
CVE ID CVE-2018-8245
CVSSv3 7.7 [CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]
CWE ID CWE-399
Exploitation vector Network
Public exploit N/A
Vulnerable software Microsoft Publisher
Vulnerable software versions Microsoft Publisher 2010
Vendor URL Microsoft

Security Advisory

1) Resource management error

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to an error when processing OLE objects within Microsoft Publisher documents. The application does not properly utilize features that locks down the Local Machine zone when instantiating OLE objects. As a result, the attacker can create a specially crafted Microsoft Publisher document, trick the user to open it and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.

Remediation

Install updates from vendor's website.

External links

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8245

Back to List