#VU11712 Information disclosure in Microsoft products - CVE-2018-0950
Published: April 10, 2018 / Updated: April 10, 2018
Microsoft Office
Microsoft Word
Microsoft Office Compatibility Pack
Microsoft
Description
The vulnerability allows a remote attacker to obtain potentially sensitive information.
The vulnerability exists due to the way Microsoft Office renders Rich Text Format (RTF) email messages containing OLE objects when a message is opened or previewed. A remote attacker can create a specially crafted email message in RTF format, initiate connection to a remote SMB server via a specially crafted OLE object and gain access to sensitive information, such as user credentials.