Security restrictions bypass in Microsoft products - CVE-2018-0907
Published: March 13, 2018 / Updated: March 13, 2018
Vulnerability identifier: #VU11051
CSH Severity: Medium
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-0907
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass certain security restrictions.
The vulnerability exists in in Microsoft Office software by not enforcing macro settings on an Excel document. A remote attacker can trick the victim to open a specially crafted Excel document and change default behavior of Microsoft Excel.
The vulnerability exists in in Microsoft Office software by not enforcing macro settings on an Excel document. A remote attacker can trick the victim to open a specially crafted Excel document and change default behavior of Microsoft Excel.
Affected software
Microsoft Excel
Microsoft Office for macOS
Microsoft Office
Microsoft Office for macOS
Microsoft Office
How to mitigate CVE-2018-0907
Install updates from vendor's website.