CVE-2018-0795

4 documents4 sources
Severity
8.8HIGH
EPSS
36.0%
top 2.91%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 10
Latest updateMay 13

Description

Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Office Remote Code Execution Vulnerability".

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages3 packages

NVDmicrosoft/office2010, 2016+1
CVEListV5microsoft_corporation/microsoft_officeMicrosoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016
NVDmicrosoft/word2013

Patches

🔴Vulnerability Details

2
GHSA
GHSA-cgjw-gcp3-vh4m: Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due to the way objects are handled2022-05-13
CVEList
CVE-2018-0795: Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due to the way objects are handled2018-01-10

📋Vendor Advisories

1
Microsoft
Microsoft Office Remote Code Execution Vulnerability2018-01-09
CVE-2018-0795 (HIGH CVSS 8.8) | Microsoft Office 2010 | cvebase.io