Information Disclosure Vulnerability in Microsoft Excel Products
CVE-2018-8429
5.5MEDIUM
Key Information:
- Vendor
- Microsoft
- Vendor
- CVE Published:
- 13 September 2018
Summary
An information disclosure vulnerability exists in Microsoft Excel which can lead to the unintended exposure of data from the application's memory. This situation arises when Excel fails to appropriately manage the contents of its memory, potentially allowing malicious actors to retrieve sensitive information. The affected products include Microsoft Excel Viewer and Microsoft Office, highlighting the need for users to stay vigilant about updates and the implementation of security patches.
Affected Version(s)
Microsoft Excel 2010 Service Pack 2 (32-bit editions)
Microsoft Excel 2010 Service Pack 2 (64-bit editions)
Microsoft Excel 2013 RT Service Pack 1
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved