Lucene search

K
nvd[email protected]NVD:CVE-2018-1028
HistoryApr 12, 2018 - 1:29 a.m.

CVE-2018-1028

2018-04-1201:29:10
CWE-94
web.nvd.nist.gov
8

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.135

Percentile

95.7%

A remote code execution vulnerability exists when the Office graphics component improperly handles specially crafted embedded fonts, aka “Microsoft Office Graphics Remote Code Execution Vulnerability.” This affects Word, Microsoft Office, Microsoft SharePoint, Excel, Microsoft SharePoint Server.

Affected configurations

Nvd
Node
microsoftexcel_servicesMatch-
OR
microsoftofficeMatch2013sp1
OR
microsoftofficeMatch2013_rtsp1
OR
microsoftofficeMatch2016
OR
microsoftoffice_2010sp2
OR
microsoftoffice_web_appsMatch2010sp2
OR
microsoftoffice_web_appsMatch2013sp1
OR
microsoftsharepoint_enterprise_serverMatch2013sp1
OR
microsoftsharepoint_enterprise_serverMatch2016
OR
microsoftword_automation_servicesMatch-
VendorProductVersionCPE
microsoftexcel_services-cpe:2.3:a:microsoft:excel_services:-:*:*:*:*:*:*:*
microsoftoffice2013cpe:2.3:a:microsoft:office:2013:sp1:*:*:*:*:*:*
microsoftoffice2013_rtcpe:2.3:a:microsoft:office:2013_rt:sp1:*:*:*:*:*:*
microsoftoffice2016cpe:2.3:a:microsoft:office:2016:*:*:*:*:*:*:*
microsoftoffice_2010*cpe:2.3:a:microsoft:office_2010:*:sp2:*:*:*:*:*:*
microsoftoffice_web_apps2010cpe:2.3:a:microsoft:office_web_apps:2010:sp2:*:*:*:*:*:*
microsoftoffice_web_apps2013cpe:2.3:a:microsoft:office_web_apps:2013:sp1:*:*:*:*:*:*
microsoftsharepoint_enterprise_server2013cpe:2.3:a:microsoft:sharepoint_enterprise_server:2013:sp1:*:*:*:*:*:*
microsoftsharepoint_enterprise_server2016cpe:2.3:a:microsoft:sharepoint_enterprise_server:2016:*:*:*:*:*:*:*
microsoftword_automation_services-cpe:2.3:a:microsoft:word_automation_services:-:*:*:*:*:*:*:*

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.135

Percentile

95.7%