Remote Code Execution Vulnerability in Microsoft PowerPoint Software
CVE-2018-8628

7.8HIGH

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
12 December 2018

Summary

A remote code execution vulnerability in Microsoft PowerPoint arises when the application improperly manages objects in memory. This flaw could allow an attacker to execute arbitrary code on the affected system, posing a significant security risk to users of Microsoft Office and related products. Users who open a maliciously crafted PowerPoint file or view malicious content in a share could inadvertently expose their systems to the attack. This vulnerability affects various Microsoft offerings, including PowerPoint Viewer and SharePoint Server. It is crucial for users and organizations to apply the necessary patches to mitigate potential risks associated with this vulnerability.

Affected Version(s)

Microsoft Office 2016 for Mac

Microsoft Office 2019 for 32-bit editions

Microsoft Office 2019 for 64-bit editions

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.