Lucene search

K
cveMicrosoftCVE-2018-0792
HistoryJan 10, 2018 - 1:29 a.m.

CVE-2018-0792

2018-01-1001:29:00
CWE-787
microsoft
web.nvd.nist.gov
67
cve-2018-0792
microsoft word
remote code execution
memory handling
microsoft office 2016

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

8.8

Confidence

High

EPSS

0.15

Percentile

95.9%

Microsoft Word 2016 in Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka “Microsoft Word Remote Code Execution Vulnerability”. This CVE is unique from CVE-2018-0794.

Affected configurations

Nvd
Vulners
Node
microsoftofficeMatch2016mac_os_x
OR
microsoftofficeMatch2016c2r
OR
microsoftoffice_online_serverMatch2016
OR
microsoftsharepoint_serverMatch2016
OR
microsoftwordMatch2016
VendorProductVersionCPE
microsoftoffice2016cpe:2.3:a:microsoft:office:2016:*:*:*:*:mac_os_x:*:*
microsoftoffice2016cpe:2.3:a:microsoft:office:2016:c2r:*:*:*:*:*:*
microsoftoffice_online_server2016cpe:2.3:a:microsoft:office_online_server:2016:*:*:*:*:*:*:*
microsoftsharepoint_server2016cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:*:*:*:*
microsoftword2016cpe:2.3:a:microsoft:word:2016:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Microsoft Word",
    "vendor": "Microsoft Corporation",
    "versions": [
      {
        "status": "affected",
        "version": "Microsoft Word 2016 and Microsoft SharePoint Enterprise Server 2016"
      }
    ]
  }
]

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

8.8

Confidence

High

EPSS

0.15

Percentile

95.9%