cbcvebase.
CVE-2018-0797
published 2018-01-10

CVE-2018-0797: Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due to the way RTF content is handled, aka…

high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due to the way RTF content is handled, aka "Microsoft Word Memory Corruption Vulnerability".

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftoffice
microsoftoffice
microsoftoffice
microsoftoffice
microsoftoffice_online_server
microsoftoffice_web_apps
microsoftoffice_web_apps_server
microsoftsharepoint_enterprise_server
microsoftsharepoint_enterprise_server
microsoftsharepoint_server
microsoftword
microsoftword
microsoftword
microsoftword
microsoft_corporationequation_editor
msrcmicrosoft_office_2010_service_pack_2
msrcmicrosoft_office_2016_for_mac
msrcmicrosoft_office_compatibility_pack_service_pack_3
msrcmicrosoft_office_online_server_2016
msrcmicrosoft_office_web_apps_2010_service_pack_2
msrcmicrosoft_office_web_apps_server_2013_service_pack_1
msrcmicrosoft_office_word_viewer
msrcmicrosoft_sharepoint_enterprise_server_2013_service_pack_1
msrcmicrosoft_sharepoint_enterprise_server_2016
msrcmicrosoft_sharepoint_server_2010_service_pack_2

CVSS provenance

nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H