Remote Code Execution Vulnerability in Microsoft Excel
CVE-2018-8577
Key Information:
- Vendor
Microsoft
- Vendor
- CVE Published:
- 14 November 2018
What is CVE-2018-8577?
A remote code execution vulnerability arises in Microsoft Excel when the application inadequately manages objects in memory. Attackers can exploit this flaw to execute arbitrary code in the context of the user, potentially leading to unauthorized operations within the affected software. This vulnerability impacts multiple Microsoft products, including Excel, Office, and Office 365 ProPlus, emphasizing the importance of implementing timely security updates to mitigate risks.
Affected Version(s)
Excel Services on Microsoft SharePoint Server 2010 Service Pack 2
Microsoft Excel 2010 Service Pack 2 (32-bit editions)
Microsoft Excel 2010 Service Pack 2 (64-bit editions)
References
EPSS Score
18% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved