Information Disclosure Vulnerability in Microsoft Office Products
CVE-2018-8427
5.5MEDIUM
Key Information:
- Vendor
- Microsoft
- Vendor
- CVE Published:
- 10 October 2018
Summary
An information disclosure vulnerability exists within Microsoft Graphics Components, which improperly handles objects in memory. This issue could allow an attacker to access sensitive information from affected Microsoft Office products, such as documents viewed or processed by applications like Microsoft Word, PowerPoint, or Excel. By specifically crafting a malicious file that exploits this vulnerability, attackers may gather data that should remain confidential. Users are encouraged to apply the latest security updates from Microsoft to mitigate this risk.
Affected Version(s)
Microsoft Excel Viewer 2007 Service Pack 3
Microsoft Office 2016 for Mac
Microsoft Office 2019 for 32-bit editions
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved