Information disclosure in Microsoft products - CVE-2018-8427

 

Information disclosure in Microsoft products - CVE-2018-8427

Published: October 9, 2018 / Updated: October 9, 2018


Vulnerability identifier: #VU15265
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-8427
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to obtain potentially sensitive information.

The vulnerability exists due to boundary error when Microsoft Graphics Components handle objects in memory. A remote attacker can trick the victim into opening a specially crafted file, trigger memory corruption and gain access to potentially sensitive information.


Affected software

Microsoft Word
Microsoft PowerPoint
Microsoft Office Compatibility Pack
Microsoft Excel
Microsoft Office
Microsoft Office for macOS
Windows Server

How to mitigate CVE-2018-8427

Install updates from vendor's website.


External References

Related Security Bulletins