Lucene search

K
cveMicrosoftCVE-2018-8627
HistoryDec 12, 2018 - 12:29 a.m.

CVE-2018-8627

2018-12-1200:29:01
CWE-908
microsoft
web.nvd.nist.gov
64
cve-2018-8627
information disclosure
microsoft excel
microsoft office
office 365 proplus
excel viewer

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

AI Score

4.9

Confidence

High

EPSS

0.003

Percentile

66.3%

An information disclosure vulnerability exists when Microsoft Excel software reads out of bound memory due to an uninitialized variable, which could disclose the contents of memory, aka “Microsoft Excel Information Disclosure Vulnerability.” This affects Microsoft Office, Office 365 ProPlus, Microsoft Excel, Microsoft Excel Viewer, Excel. This CVE ID is unique from CVE-2018-8598.

Affected configurations

Nvd
Vulners
Node
microsoftexcelMatch2010sp2
OR
microsoftexcelMatch2013sp1
OR
microsoftexcelMatch2013sp1rt
OR
microsoftexcelMatch2016
OR
microsoftexcel_viewerMatch2007sp3
OR
microsoftofficeMatch2010sp2
OR
microsoftofficeMatch2016mac_os_x
OR
microsoftofficeMatch2019
OR
microsoftofficeMatch2019macos
OR
microsoftoffice_365_proplusMatch-
OR
microsoftoffice_compatibility_packMatch-sp3
OR
microsoftsharepoint_serverMatch2010sp2
VendorProductVersionCPE
microsoftexcel2010cpe:2.3:a:microsoft:excel:2010:sp2:*:*:*:*:*:*
microsoftexcel2013cpe:2.3:a:microsoft:excel:2013:sp1:*:*:*:*:*:*
microsoftexcel2013cpe:2.3:a:microsoft:excel:2013:sp1:*:*:rt:*:*:*
microsoftexcel2016cpe:2.3:a:microsoft:excel:2016:*:*:*:*:*:*:*
microsoftexcel_viewer2007cpe:2.3:a:microsoft:excel_viewer:2007:sp3:*:*:*:*:*:*
microsoftoffice2010cpe:2.3:a:microsoft:office:2010:sp2:*:*:*:*:*:*
microsoftoffice2016cpe:2.3:a:microsoft:office:2016:*:*:*:*:mac_os_x:*:*
microsoftoffice2019cpe:2.3:a:microsoft:office:2019:*:*:*:*:*:*:*
microsoftoffice2019cpe:2.3:a:microsoft:office:2019:*:*:*:*:macos:*:*
microsoftoffice_365_proplus-cpe:2.3:a:microsoft:office_365_proplus:-:*:*:*:*:*:*:*
Rows per page:
1-10 of 121

CNA Affected

[
  {
    "product": "Microsoft Office",
    "vendor": "Microsoft",
    "versions": [
      {
        "status": "affected",
        "version": "2010 Service Pack 2 (32-bit editions)"
      },
      {
        "status": "affected",
        "version": "2010 Service Pack 2 (64-bit editions)"
      },
      {
        "status": "affected",
        "version": "2016 for Mac"
      },
      {
        "status": "affected",
        "version": "2019 for 32-bit editions"
      },
      {
        "status": "affected",
        "version": "2019 for 64-bit editions"
      },
      {
        "status": "affected",
        "version": "2019 for Mac"
      },
      {
        "status": "affected",
        "version": "Compatibility Pack Service Pack 3"
      }
    ]
  },
  {
    "product": "Microsoft Excel",
    "vendor": "Microsoft",
    "versions": [
      {
        "status": "affected",
        "version": "2010 Service Pack 2 (32-bit editions)"
      },
      {
        "status": "affected",
        "version": "2010 Service Pack 2 (64-bit editions)"
      },
      {
        "status": "affected",
        "version": "2013 RT Service Pack 1"
      },
      {
        "status": "affected",
        "version": "2013 Service Pack 1 (32-bit editions)"
      },
      {
        "status": "affected",
        "version": "2013 Service Pack 1 (64-bit editions)"
      },
      {
        "status": "affected",
        "version": "2016 (32-bit edition)"
      },
      {
        "status": "affected",
        "version": "2016 (64-bit edition)"
      }
    ]
  },
  {
    "product": "Microsoft Excel Viewer",
    "vendor": "Microsoft",
    "versions": [
      {
        "status": "affected",
        "version": "2007 Service Pack 3"
      }
    ]
  },
  {
    "product": "Excel",
    "vendor": "Microsoft",
    "versions": [
      {
        "status": "affected",
        "version": "Services on Microsoft SharePoint Server 2010 Service Pack 2"
      }
    ]
  },
  {
    "product": "Office",
    "vendor": "Microsoft",
    "versions": [
      {
        "status": "affected",
        "version": "365 ProPlus for 32-bit Systems"
      },
      {
        "status": "affected",
        "version": "365 ProPlus for 64-bit Systems"
      }
    ]
  }
]

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

AI Score

4.9

Confidence

High

EPSS

0.003

Percentile

66.3%