Information disclosure in Microsoft products - CVE-2018-8427
Published: October 9, 2018 / Updated: October 9, 2018
Vulnerability details
The vulnerability allows a remote attacker to obtain potentially sensitive information.
The vulnerability exists due to boundary error when Microsoft Graphics Components handle objects in memory. A remote attacker can trick the victim into opening a specially crafted file, trigger memory corruption and gain access to potentially sensitive information.
Affected software
Microsoft PowerPoint
Microsoft Office Compatibility Pack
Microsoft Excel
Microsoft Office
Microsoft Office for macOS
Windows Server