CVE-2018-0797
published 2018-01-10CVE-2018-0797: Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due to the way RTF content is handled, aka…
PriorityP349high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
24.76%
97.7th percentile
Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due to the way RTF content is handled, aka "Microsoft Word Memory Corruption Vulnerability".
Affected
30 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | office_online_server | — | — |
| microsoft | office_web_apps | — | — |
| microsoft | office_web_apps_server | — | — |
| microsoft | sharepoint_enterprise_server | — | — |
| microsoft | sharepoint_enterprise_server | — | — |
| microsoft | sharepoint_server | — | — |
| microsoft | word | — | — |
| microsoft | word | — | — |
| microsoft | word | — | — |
| microsoft | word | — | — |
| microsoft_corporation | equation_editor | — | — |
| msrc | microsoft_office_2010_service_pack_2 | — | — |
| msrc | microsoft_office_2016_for_mac | — | — |
| msrc | microsoft_office_compatibility_pack_service_pack_3 | — | — |
| msrc | microsoft_office_online_server_2016 | — | — |
| msrc | microsoft_office_web_apps_2010_service_pack_2 | — | — |
| msrc | microsoft_office_web_apps_server_2013_service_pack_1 | — | — |
| msrc | microsoft_office_word_viewer | — | — |
| msrc | microsoft_sharepoint_enterprise_server_2013_service_pack_1 | — | — |
| msrc | microsoft_sharepoint_enterprise_server_2016 | — | — |
| msrc | microsoft_sharepoint_server_2010_service_pack_2 | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_msrc7.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f2vj-ccgm-xw84: Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due to the way RTF content is hand
ghsa_unreviewed·2022-05-13
CVE-2018-0797 [HIGH] CWE-787 GHSA-f2vj-ccgm-xw84: Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due to the way RTF content is hand
Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due to the way RTF content is handled, aka "Microsoft Word Memory Corruption Vulnerability".
GHSA
GHSA-x323-9hmm-gv8q: Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulner
ghsa_unreviewed·2022-05-13·CVSS 7.8
CVE-2018-0802 [HIGH] CWE-787 GHSA-x323-9hmm-gv8q: Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulner
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE is unique from CVE-2018-0797 and CVE-2018-0812.
Microsoft
Microsoft Office Memory Corruption Vulnerability
vendor_msrc·2018-01-09·CVSS 7.8
CVE-2018-0797 [HIGH] Microsoft Office Memory Corruption Vulnerability
Microsoft Office Memory Corruption Vulnerability
Description: An Office RTF remote code execution vulnerability exists in Microsoft Office software when the Office software fails to properly handle RTF files. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
Exploitation of the vulnerability requires that a user open a specially crafted
No detection rules found.
No public exploits indexed.
Fortinet
Navigating Cybersecurity Challenges with the Essential Eight | Fortinet Blog
blogs_fortinet·2024-02-23
Navigating Cybersecurity Challenges with the Essential Eight | Fortinet Blog
INDUSTRY TRENDS & INSIGHTS
Navigating Cybersecurity Challenges with the Essential Eight
By Fortinet | February 23, 2024
Cybercriminals continue to target critical infrastructure for substantial financial gain while also strategically attacking third-party vendors. And because, like any enterprise, they aim to maximize the returns on their investments in these attacks, their approach is both aggressive and persistent. To effectively defend themselves from these campaigns, businesses need to proactively manage their cyber risk to reduce the implications of a cyberattack, including revenue loss, loss of intellectual property, brand erosion, reputation damage, upstream and downstream victims, and even regulatory fines and penalties.
The Essential Eight framework, developed by the Australian
Fortinet
Another Local Privilege Escalation Vulnerability Using Process Creation Impersonation
blogs_fortinet·2019-09-10
Another Local Privilege Escalation Vulnerability Using Process Creation Impersonation
FORTIGUARD LABS THREAT RESEARCH
Another Local Privilege Escalation (LPE) Vulnerability Using Process Creation Impersonation
By Wayne Chin Yick Low | September 10, 2019
Introduction
Over the past few months, FortiGuard Labs has been working closely with the Microsoft Security Response Centre (MSRC) to address multiple local privilege escalation (LPE) vulnerabilities that we discovered on the Windows platform. One of the most notable LPE vulnerabilities we reported to MSRC was found on the Windows Network Connectivity Assistant (NCA), which is only enabled on the Enterprise or Education versions of Microsoft Windows 10. The nature of this LPE vulnerability had previously been reported to MSRC as proof-of-concept (POC) by James Forshaw, an author and security researcher in Google's Project
Fortinet
“BlueKeep” Vulnerability (CVE-2019-0708) within Cloud/Datacenter Machines: How to Safeguard Yourself?
blogs_fortinet·2019-06-12·CVSS 9.8
CVE-2019-0708 [CRITICAL] “BlueKeep” Vulnerability (CVE-2019-0708) within Cloud/Datacenter Machines: How to Safeguard Yourself?
FORTIGUARD LABS THREAT RESEARCH
“BlueKeep” Vulnerability (CVE-2019-0708) within Cloud/Datacenter Machines: How to Safeguard Yourself?
By Kushal Arvind Shah | June 12, 2019
Afew weeks back, FortiGuard Labs heard of the BlueKeep RDP Wormable Vulnerability [CVE-2019-0708]. According to Microsoft, this vulnerability affects the Remote Desktop Protocol (RDP) service included in older versions of Windows OS, such as Windows XP, Windows Vista, Windows 7, Windows Server 2003, Windows Server 2008, and Windows Server 2008R2.
Recently, there was an article by Robert Graham of Errata Security saying that nearly 1 million machines are still vulnerable to this critical vulnerability. Microsoft and even the NSA have recently issued advisories asking users to patch their systems to avoid another attack
Fortinet
Detailed Analysis of macOS Vulnerability CVE-2019-8507
blogs_fortinet·2019-04-23·CVSS 5.5
CVE-2019-8507 [MEDIUM] Detailed Analysis of macOS Vulnerability CVE-2019-8507
FORTIGUARD LABS THREAT RESEARCH
Detailed Analysis of macOS Vulnerability CVE-2019-8507
By Kai Lu | April 23, 2019
FortiGuard Labs Threat Analysis Report on an Memory Corruption Vulnerability in QuartzCore while Handling Shape Object.
On March 25, 2019, Apple released macOS Mojave 10.14.4 and iOS 12.2. These two updates fixed a number of security vulnerabilities, including CVE-2019-8507 in QuartzCore (aka CoreAnimation), which I reported to Apple on January 3, 2019 using our FortiGuard Labs responsible disclosure process, read more. For more details on the Apple updates, please refer to https://support.apple.com/en-us/HT209600. In this blog I will provide a detailed analysis of this issue on macOS. Some of the analysis techniques used can be found in my previous blog, “Detailed Analysi
Securelist
New zero-day vulnerability CVE-2019-0859 in win32k.sys
blogs_securelist·2019-04-15·CVSS 7.8
[HIGH] New zero-day vulnerability CVE-2019-0859 in win32k.sys
Authors
Vasily Berdnikov
Boris Larin
Anton Ivanov
In March 2019, our automatic Exploit Prevention (EP) systems detected an attempt to exploit a vulnerability in the Microsoft Windows operating system. Further analysis of this event led to us discovering a zero-day vulnerability in win32k.sys. It was the fifth consecutive exploited Local Privilege Escalation vulnerability in Windows that we have discovered in recent months using our technologies. The previous ones were:
Zero-day exploit (CVE-2018-8453) used in targeted attacks
A new exploit for zero-day vulnerability CVE-2018-8589
Zero-day in Windows Kernel Transaction Manager (CVE-2018-8611)
The fourth horseman: CVE-2019-0797 vulnerability
On March 17, 2019 we reported our discovery to Microsoft; the company confirmed the vulnerab
Fortinet
Patch Your Microsoft Windows and Office: Fortinet Discovers Three Zero-Day Remote Code Execution Vulnerabilities
blogs_fortinet·2019-04-10·CVSS 7.8
[HIGH] Patch Your Microsoft Windows and Office: Fortinet Discovers Three Zero-Day Remote Code Execution Vulnerabilities
FORTIGUARD LABS THREAT RESEARCH
Patch Your Microsoft Windows and Office: Fortinet Discovers Three Zero-Day Remote Code Execution Vulnerabilities
By Honggang Ren | April 10, 2019
AFortiGuard Labs Breaking Threat Research Report
On the April 9, 2019 Patch Tuesday, Microsoft released patches for several vulnerabilities in Windows and Office. Three of them were discovered and reported by FortiGuard Labs researcher Honggang Ren by following Fortinet’s responsible disclosure process. The CVE numbers assigned to them are CVE-2019-0825, CVE-2019-0851 and CVE-2019-0877. Two of them are related to Microsoft Jet Database Engine. The other is related to the Microsoft Office Access Connectivity Engine, which is an Office-specific version of the Jet Database Engine. All three of these vulnerabiliti
Fortinet
Microsoft Windows JET Database Engine Heap Overflow Vulnerability
blogs_fortinet·2018-04-11·CVSS 7.8
CVE-2018-1003 [HIGH] Microsoft Windows JET Database Engine Heap Overflow Vulnerability
FORTIGUARD LABS THREAT RESEARCH
Microsoft Windows JET Database Engine Heap Overflow Vulnerability
By Honggang Ren | April 11, 2018
At the end of 2017, the FortiGuard Labs team discovered a heap overflow vulnerability in Microsoft Windows JET Database Engine and reported it to Microsoft following Fortinet’s responsible disclosure process. On April 10, 2018, Microsoft released an advisory that contains the fix for this vulnerability and identifies it as CVE-2018-1003.
This heap overflow vulnerability exists in the Microsoft JET Database Engine’s dynamic link library “msexcl40.dll”, which has a long history. It was first introduced in Windows 2000, and is a component of all supported Windows versions from Windows 7 to Windows 10.
The vulnerability I discovered can be triggered with a craf
Fortinet
A root cause analysis of CVE-2018-0797 - Rich Text Format Stylesheet Use-After-Free vulnerability
blogs_fortinet·2018-04-01·CVSS 7.8
CVE-2018-0797 [HIGH] A root cause analysis of CVE-2018-0797 - Rich Text Format Stylesheet Use-After-Free vulnerability
FORTIGUARD LABS THREAT RESEARCH
A root cause analysis of CVE-2018-0797 - Rich Text Format Stylesheet Use-After-Free vulnerability
By Wayne Chin Yick Low | April 01, 2018
Over the last few months, the Microsoft Security Response Centre (MSRC) has released a number of Windows updates to fix multiple Use-After-Free (UAF) vulnerabilities discovered by FortiGuard Labs. As stated in our previous blog post, we will provide a technical write-up for one of the UAF issues that was rated as critical by MSRC. The issue is assigned to CVE-2018-0797. In this blog post we will share our methodologies in identifying the root cause of the issue, as well as an analysis of the mitigation deployed by Microsoft to address the UAF vulnerability.
Please take note that the following analysis was performed on M
Fortinet
FortiGuard Labs Discovers Multiple Use-After-Free Vulnerabilities in Microsoft Word
blogs_fortinet·2018-03-22·CVSS 7.8
[HIGH] FortiGuard Labs Discovers Multiple Use-After-Free Vulnerabilities in Microsoft Word
FORTIGUARD LABS THREAT RESEARCH
FortiGuard Labs Discovers Multiple Use-After-Free Vulnerabilities in Microsoft Word
By Wayne Chin Yick Low | March 22, 2018
During the last few months, FortiGuard Labs discovered and reported multiple use-after-free (UAF) vulnerabilities found in different versions of Microsoft Word. These vulnerabilities were patched in the January and March security updates, respectively. These patches are rated as critical/important, and as always, we urge users update Microsoft Office as soon as possible.
Use-after-free refers to a vulnerability that allows an attacker to access memory after it has been freed, which can cause a program to crash, allow the execution of arbitrary code, or even enable full remote code execution. Following are some details of the UAF vuln
Talos
Microsoft Patch Tuesday - January 2018
blogs_talos·2018-01-09·CVSS 7.5
[HIGH] Microsoft Patch Tuesday - January 2018
## Microsoft Patch Tuesday - January 2018
Today Microsoft has released its monthly set of security advisories for vulnerabilities that have been identified and addressed in various products. This month's advisory release addresses 56 new vulnerabilities with 16 of them rated critical, 39 of them rated important and 1 of them rated Moderate. These vulnerabilities impact ASP.NET, Edge, Internet Explorer, Office, Windows, and more.
In addition to the 56 vulnerabilities addressed, Microsoft has also released an update that addresses Meltdown and Spectre. Mitigations for these two vulnerabilities were published for Windows in ADV180002 . Note that due to incompatibilities with anti-virus products, users and organizations may not have received this update yet. For more information, users shoul
Talos
Microsoft Patch Tuesday - January 2018
blogs_talos·2018-01-09·CVSS 7.5
[HIGH] Microsoft Patch Tuesday - January 2018
Today Microsoft has released its monthly set of security advisories for vulnerabilities that have been identified and addressed in various products. This month's advisory release addresses 56 new vulnerabilities with 16 of them rated critical, 39 of them rated important and 1 of them rated Moderate. These vulnerabilities impact ASP.NET, Edge, Internet Explorer, Office, Windows, and more.
In addition to the 56 vulnerabilities addressed, Microsoft has also released an update that addresses Meltdown and Spectre. Mitigations for these two vulnerabilities were published for Windows in ADV180002. Note that due to incompatibilities with anti-virus products, users and organizations may not have received this update yet. For more information, users should refer to Microsoft's knowledge base articl
Fortinet
An Inside Look at CVE-2017-0199 – HTA and Scriptlet File Handler Vulnerability
blogs_fortinet·2017-06-04·CVSS 7.8
CVE-2017-0199 [HIGH] An Inside Look at CVE-2017-0199 – HTA and Scriptlet File Handler Vulnerability
FORTIGUARD LABS THREAT RESEARCH
An Inside Look at CVE-2017-0199 – HTA and Scriptlet File Handler Vulnerability
By Wayne Chin Yick Low | June 04, 2017
FortiGuard Labs recently came across a new strain of samples exploiting the CVE-2017-0199 vulnerability. This vulnerability was fixed by Microsoft and the patch was released in April 2017. Due to its simplicity, it can be easily exploited by attackers. It has also been found in-the-wild by other vendors. We have also blogged about some samples recently found in spear phishing attack.
While there are plenty of articles discussing this vulnerability, most of them are intended for technical readers and primarily focus on how to create proof-of-concept (POC) for the vulnerability. If you are looking for an easy-to-understand article, we found
Fortinet
Remote Password Change Vulnerability in HPE Vertica Analytic Database
blogs_fortinet·2017-04-20·CVSS 9.8
CVE-2017-5802 [CRITICAL] Remote Password Change Vulnerability in HPE Vertica Analytic Database
FORTIGUARD LABS THREAT RESEARCH
Remote Password Change Vulnerability in HPE Vertica Analytic Database
By Honggang Ren | April 20, 2017
Summary
On March 24 2017, I discovered and reported on a remote password change vulnerability in Hewlett-Packard Enterprise’s (HPE) Vertica Analytic Database. This week, HPE released Security Bulletin HPESBGN03734, which contains the fix for this vulnerability and identifies it as CVE-2017-5802.
Fueled by ever-growing volumes of Big Data found in many corporations and government agencies, HPE's Vertica Analytics Platform provides an SQL analytics solution built from the ground up to handle massive volumes of data and delivers blazingly fast Big Data analytics. At the core of the Vertica Analytics Platform is a column-oriented, relational database named V
Fortinet
iSNS Server Memory Corruption Vulnerability in Microsoft Windows Server
blogs_fortinet·2017-03-23·CVSS 8.1
CVE-2017-0104 [HIGH] iSNS Server Memory Corruption Vulnerability in Microsoft Windows Server
FORTIGUARD LABS THREAT RESEARCH
iSNS Server Memory Corruption Vulnerability in Microsoft Windows Server
By Honggang Ren | March 23, 2017
Summary
In November 2016, as part of my FortiGuard research work, I discovered and reported on an iSNS server memory corruption vulnerability in Microsoft Windows Server. On patch Tuesday of March 2017, Microsoft released the Security Bulletin MS17-012 that contain the fix for this vulnerability and identifies it as CVE-2017-0104.
This vulnerability could lead to remote code execution, and is rated as critical by Microsoft. The vulnerability affects Windows Server 2008, 2012, and 2016 versions. Microsoft recommends installing this update immediately.
In this blog I will share the details of this vulnerability.
How to Reproduce
To reproduce the vulne
Fortinet
Looking Back at Fortinet’s Security Research and Vulnerability Discoveries
blogs_fortinet·2017-02-21
Looking Back at Fortinet’s Security Research and Vulnerability Discoveries
FORTIGUARD LABS THREAT RESEARCH
Looking Back at Fortinet’s Security Research and Vulnerability Discoveries
By Peixue Li | February 21, 2017
In an effort to provide more proactive protections in Fortinet products and to more effectively identify and defeat network threats, the Fortinet security research team works on discovering potential threats in popular products. As a result, over the past year we have discovered 84 vulnerabilities that have been reported to their respective vendors as part of our responsible vulnerability disclosure process. Fortinet protections against these discoveries were released to Fortinet products at the same time these vulnerabilities were reported to their vendors. As a result, Fortinet products have been able to proactively protect Fortinet customers’ netw
Fortinet
Microsoft Kernel Integer Overflow Vulnerability
blogs_fortinet·2016-10-31·CVSS 5.5
CVE-2016-0070 [MEDIUM] Microsoft Kernel Integer Overflow Vulnerability
FORTIGUARD LABS THREAT RESEARCH
Microsoft Kernel Integer Overflow Vulnerability
By Honggang Ren | October 31, 2016
Last month I discovered and reported an integer overflow vulnerability in the Windows Registry. Last Tuesday, October 25th, Microsoft released Security Bulletin MS16-124, which contains the patch for this vulnerability, and identifies it as CVE-2016-0070.
This vulnerability could lead to local privilege elevation, and is rated as “Important” by Microsoft. The vulnerability affects multiple Windows versions, and Microsoft has recommended installing this update immediately.
In this blog I will share the details of this vulnerability.
How to Reproduce
To reproduce the vulnerability, follow the steps below.
Sign into Windows 7 with any non-admin account.
Run regedit.exe in
Fortinet
Analysis of OpenSSL Large Message Size Handling Use After Free (CVE-2016-6309)
blogs_fortinet·2016-10-12·CVSS 5.9
CVE-2016-6309 [MEDIUM] Analysis of OpenSSL Large Message Size Handling Use After Free (CVE-2016-6309)
FORTIGUARD LABS THREAT RESEARCH
Analysis of OpenSSL Large Message Size Handling Use After Free (CVE-2016-6309)
By Dehui Yin | October 12, 2016
OpenSSL released an emergency security update shortly after a patch was issued a few weeks ago. This security update addresses a critical Use After Free vulnerability introduced by the updated code that revised to resolve the earlier low severity vulnerability CVE-2016-6307.
This critical Use After Free vulnerability (CVE-2016-6309) is caused by an error that occurs when relocating a message with an overlarge message size greater than 16k. Remote attackers may access the freed buffer to crash, or potentially even execute arbitrary code on vulnerable systems.
This Use After Free vulnerability only affects OpenSSL version 1.1.0a. In this report we
Zscaler
Zscaler found Multiple Security Vulnerabilities | 01-09-2018
blogs_zscaler·CVSS 7.5
[HIGH] Zscaler found Multiple Security Vulnerabilities | 01-09-2018
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
http://www.securityfocus.com/bid/102406http://www.securitytracker.com/id/1040153https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0797http://www.securityfocus.com/bid/102406http://www.securitytracker.com/id/1040153https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0797
2018-01-10
Published