Lucene search

K
cveMicrosoftCVE-2018-8432
HistoryOct 10, 2018 - 1:29 p.m.

CVE-2018-8432

2018-10-1013:29:02
microsoft
web.nvd.nist.gov
81
microsoft
graphics components
remote code execution
vulnerability
windows 7
office
office 365 proplus
excel viewer
powerpoint viewer
windows server 2019
windows 10
nvd
cve-2018-8432

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

8.2

Confidence

High

EPSS

0.306

Percentile

97.0%

A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka “Microsoft Graphics Components Remote Code Execution Vulnerability.” This affects Windows 7, Microsoft Office, Microsoft Office Word Viewer, Office 365 ProPlus, Microsoft Excel Viewer, Microsoft PowerPoint Viewer, Windows Server 2019, Windows Server 2008 R2, Windows 10, Windows Server 2008.

Affected configurations

Nvd
Vulners
Node
microsoftexcel_viewerMatch2007sp3
OR
microsoftofficeMatch2016mac_os
OR
microsoftofficeMatch2019
OR
microsoftoffice_365_proplusMatch-
OR
microsoftoffice_compatibility_packMatch-sp3
OR
microsoftpowerpoint_viewerMatch2007
OR
microsoftword_viewerMatch-
OR
microsoftwindows_10Match1809
OR
microsoftwindows_7Match-sp1
OR
microsoftwindows_server_2008Match-sp2
OR
microsoftwindows_server_2008Matchr2sp1
OR
microsoftwindows_server_2019Match-
VendorProductVersionCPE
microsoftexcel_viewer2007cpe:2.3:a:microsoft:excel_viewer:2007:sp3:*:*:*:*:*:*
microsoftoffice2016cpe:2.3:a:microsoft:office:2016:*:mac_os:*:*:*:*:*
microsoftoffice2019cpe:2.3:a:microsoft:office:2019:*:*:*:*:*:*:*
microsoftoffice_365_proplus-cpe:2.3:a:microsoft:office_365_proplus:-:*:*:*:*:*:*:*
microsoftoffice_compatibility_pack-cpe:2.3:a:microsoft:office_compatibility_pack:-:sp3:*:*:*:*:*:*
microsoftpowerpoint_viewer2007cpe:2.3:a:microsoft:powerpoint_viewer:2007:*:*:*:*:*:*:*
microsoftword_viewer-cpe:2.3:a:microsoft:word_viewer:-:*:*:*:*:*:*:*
microsoftwindows_101809cpe:2.3:o:microsoft:windows_10:1809:*:*:*:*:*:*:*
microsoftwindows_7-cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:*
microsoftwindows_server_2008-cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*
Rows per page:
1-10 of 121

CNA Affected

[
  {
    "product": "Windows 7",
    "vendor": "Microsoft",
    "versions": [
      {
        "status": "affected",
        "version": "32-bit Systems Service Pack 1"
      },
      {
        "status": "affected",
        "version": "x64-based Systems Service Pack 1"
      }
    ]
  },
  {
    "product": "Microsoft Office",
    "vendor": "Microsoft",
    "versions": [
      {
        "status": "affected",
        "version": "2016 for Mac"
      },
      {
        "status": "affected",
        "version": "2019 for 32-bit editions"
      },
      {
        "status": "affected",
        "version": "2019 for 64-bit editions"
      },
      {
        "status": "affected",
        "version": "Compatibility Pack Service Pack 3"
      }
    ]
  },
  {
    "product": "Microsoft Office Word Viewer",
    "vendor": "Microsoft",
    "versions": [
      {
        "status": "affected",
        "version": "Microsoft Office Word Viewer"
      }
    ]
  },
  {
    "product": "Microsoft Excel Viewer",
    "vendor": "Microsoft",
    "versions": [
      {
        "status": "affected",
        "version": "2007 Service Pack 3"
      }
    ]
  },
  {
    "product": "Microsoft PowerPoint Viewer",
    "vendor": "Microsoft",
    "versions": [
      {
        "status": "affected",
        "version": "2007"
      }
    ]
  },
  {
    "product": "Windows Server 2019",
    "vendor": "Microsoft",
    "versions": [
      {
        "status": "affected",
        "version": "(Server Core installation)"
      }
    ]
  },
  {
    "product": "Office",
    "vendor": "Microsoft",
    "versions": [
      {
        "status": "affected",
        "version": "365 ProPlus for 32-bit Systems"
      },
      {
        "status": "affected",
        "version": "365 ProPlus for 64-bit Systems"
      }
    ]
  },
  {
    "product": "Windows Server 2008 R2",
    "vendor": "Microsoft",
    "versions": [
      {
        "status": "affected",
        "version": "Itanium-Based Systems Service Pack 1"
      },
      {
        "status": "affected",
        "version": "x64-based Systems Service Pack 1"
      },
      {
        "status": "affected",
        "version": "x64-based Systems Service Pack 1 (Server Core installation)"
      }
    ]
  },
  {
    "product": "Windows 10",
    "vendor": "Microsoft",
    "versions": [
      {
        "status": "affected",
        "version": "Version 1809 for 32-bit Systems"
      },
      {
        "status": "affected",
        "version": "Version 1809 for x64-based Systems"
      }
    ]
  },
  {
    "product": "Windows Server 2008",
    "vendor": "Microsoft",
    "versions": [
      {
        "status": "affected",
        "version": "32-bit Systems Service Pack 2"
      },
      {
        "status": "affected",
        "version": "32-bit Systems Service Pack 2 (Server Core installation)"
      },
      {
        "status": "affected",
        "version": "Itanium-Based Systems Service Pack 2"
      },
      {
        "status": "affected",
        "version": "x64-based Systems Service Pack 2"
      },
      {
        "status": "affected",
        "version": "x64-based Systems Service Pack 2 (Server Core installation)"
      }
    ]
  }
]

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

8.2

Confidence

High

EPSS

0.306

Percentile

97.0%