Out-of-bounds read in Microsoft products - CVE-2018-8382

 

Out-of-bounds read in Microsoft products - CVE-2018-8382

Published: August 14, 2018 / Updated: August 14, 2018


Vulnerability identifier: #VU14393
CSH Severity: Low
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-8382
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to boundary error when processing Excel files. A remote unauthenticated attacker can trick the victim into opening a specially crafted Excel file and gain access to sensitive information stored into memory.


Affected software

Microsoft Office Compatibility Pack
Microsoft Excel
Microsoft Office
Microsoft Office for macOS

How to mitigate CVE-2018-8382

Install updates from vendor's website.


External References

Related Security Bulletins