CVE-2018-0792 — Out-of-bounds Write in Corporation Microsoft Word
Severity
8.8HIGHNVD
EPSS
37.7%
top 2.79%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 10
Latest updateMay 13
Description
Microsoft Word 2016 in Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Remote Code Execution Vulnerability". This CVE is unique from CVE-2018-0794.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9
Affected Packages5 packages
▶CVEListV5microsoft_corporation/microsoft_wordMicrosoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016, Microsoft Word 2016 and Microsoft SharePoint Enterprise Server 2016+1
Patches
🔴Vulnerability Details
2GHSA▶
GHSA-6wj9-4q9r-266c: Microsoft Word 2016 in Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft↗2022-05-13
CVEList▶
CVE-2018-0792: Microsoft Word 2016 in Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft↗2018-01-10