Out-of-bounds read in Microsoft products - CVE-2018-8378

 

Out-of-bounds read in Microsoft products - CVE-2018-8378

Published: August 14, 2018 / Updated: August 14, 2018


Vulnerability identifier: #VU14398
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-8378
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to out-of-bounds read error when processing Microsoft Office documents. A remote unauthenticated attacker can create a specially crafted Office document, trick the victim into opening it, trigger out-of-bounds read and gain access to contents of memory.


Affected software

Microsoft Word
Microsoft Excel
Microsoft Office
Microsoft Office Web Apps
Word Automation Services on Microsoft SharePoint Server
Microsoft SharePoint Server

How to mitigate CVE-2018-8378

Install updates from vendor's website.


External References

Related Security Bulletins