Lucene search

K
mscveMicrosoftMS:CVE-2018-8393
HistorySep 11, 2018 - 7:00 a.m.

Microsoft JET Database Engine Remote Code Execution Vulnerability

2018-09-1107:00:00
Microsoft
msrc.microsoft.com
14

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.18

Percentile

96.3%

A buffer overflow vulnerability exists in the Microsoft JET Database Engine that could allow remote code execution on an affected system. An attacker who successfully exploited this vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

To exploit the vulnerability, a user must open a specially crafted Excel file while using an affected version of Microsoft Windows. In an email attack scenario, an attacker could exploit the vulnerability by sending a specially crafted Excel file to the user, and then convincing the user to open the file.

The security update addresses the vulnerability by modifying how the Microsoft JET Database Engine handles objects in memory.

Affected configurations

Vulners
Node
microsoftwindows_server_1709Range<2018-Sep
OR
microsoftwindows_server_2012Range<2018-Sepr2
OR
microsoftwindows_server_2012Range<2018-Sepr2
OR
microsoftwindows_server\,_1803_\(server_core_installation\)Range<2018-Sep
OR
microsoftwindows_server\,_1803_\(server_core_installation\)Range<2018-Sep
OR
microsoftwindows_server_2012Range<2018-Sepr2
OR
microsoftwindows_server_2012Range<2018-Sepr2
OR
microsoftwindows_server_2012Range<2018-Sep
OR
microsoftwindows_server_2012Range<2018-Sep
OR
microsoftwindows_server_2008Range<2018-Sepr2x64
OR
microsoftwindows_server_2008Range<2018-Sepr2x64
OR
microsoftwindows_server_2008Range<2018-Sepitanium
OR
microsoftwindows_server_2008Range<2018-Sepitanium
OR
microsoftwindows_defender_on_windows_10_1607_for_32-bit_systemsRange<2018-Sep
OR
microsoftwindows_10_1709_for_32-bit_systemsRange<2018-Sep
OR
microsoftwindows_server\,_1803_\(server_core_installation\)Range<2018-Sep
OR
microsoftwindows_defender_on_windows_10_1703_for_x64-based_systemsRange<2018-Sep
OR
microsoftwindows_server_2008Range<2018-Sepr2x64
OR
microsoftwindows_server_2008Range<2018-Sepr2x64
OR
microsoftwindows_server_2008_r2Range<2018-Sepsp1itanium
OR
microsoftwindows_server_2008_r2Range<2018-Sepsp1itanium
OR
microsoftwindows_server_2008Range<2018-Sepx64
OR
microsoftwindows_server_2008Range<2018-Sepx64
OR
microsoftwindows_server_2008Range<2018-Sepx64
OR
microsoftwindows_server_2008Range<2018-Sepx64
OR
microsoftwindows_server\,_1803_\(server_core_installation\)Range<2018-Sep
OR
microsoftwindows_server\,_1803_\(server_core_installation\)Range<2018-Sep
OR
microsoftwindows_10_2004_for_32-bit_systemsRange<2018-Sep
OR
microsoftwindows_10_2004_for_32-bit_systemsRange<2018-Sep
OR
microsoftwindows_10_2004_for_32-bit_systemsRange<2018-Sep
OR
microsoftwindows_10_2004_for_32-bit_systemsRange<2018-Sep
OR
microsoftwindows_10_1903_for_x64-based_systemsRange<2018-Sep
OR
microsoftwindows_10_1903_for_x64-based_systemsRange<2018-Sep
OR
microsoftwindows_rt_8.1Range<2018-Sep
OR
microsoftwindows_10_1903_for_x64-based_systemsRange<2018-Sep
OR
microsoftwindows_10_1903_for_x64-based_systemsRange<2018-Sep
OR
microsoftwindows_10_2004_for_32-bit_systemsRange<2018-Sep
OR
microsoftwindows_10_2004_for_32-bit_systemsRange<2018-Sep
OR
microsoftwindows_server\,_1803_\(server_core_installation\)Range<2018-Sep
OR
microsoftwindows_defender_on_windows_10_1607_for_x64-based_systemsRange<2018-Sep
OR
microsoftwindows_server_2016Range<2018-Sep
OR
microsoftwindows_10_1903_for_x64-based_systemsRange<2018-Sep
OR
microsoftwindows_10_2004_for_32-bit_systemsRange<2018-Sep
OR
microsoftwindows_10_1709_for_x64-based_systemsRange<2018-Sep
OR
microsoftwindows_10_1803_for_x64-based_systemsRange<2018-Sep
OR
microsoftwindows_10_1803_for_32-bit_systemsRange<2018-Sep
OR
microsoftwindows_defender_on_windows_10_1703_for_32-bit_systemsRange<2018-Sep

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.18

Percentile

96.3%