CVE-2018-0850
published 2018-02-15CVE-2018-0850: Microsoft Outlook 2007, Microsoft Outlook 2010, Microsoft Outlook 2013, Microsoft Outlook 2016, and Microsoft Office 2016 Click-to-Run allow an elevation of…
PriorityP333medium6.5CVSS 3.0
AVNACLPRNUIRSUCNIHAN
EPSS
5.13%
91.3th percentile
Microsoft Outlook 2007, Microsoft Outlook 2010, Microsoft Outlook 2013, Microsoft Outlook 2016, and Microsoft Office 2016 Click-to-Run allow an elevation of privilege vulnerability due to how the format of incoming message is validated, aka "Microsoft Outlook Elevation of Privilege Vulnerability".
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | office | — | — |
| microsoft | outlook | — | — |
| microsoft | outlook | — | — |
| microsoft | outlook | — | — |
| microsoft | outlook | — | — |
| microsoft_corporation | microsoft_outlook | — | — |
| msrc | microsoft_office_2016_click-to-run_for_32-bit_editions | — | — |
| msrc | microsoft_office_2016_click-to-run_for_64-bit_editions | — | — |
| msrc | microsoft_outlook_2007_service_pack_3 | — | — |
| msrc | microsoft_outlook_2010_service_pack_2 | — | — |
| msrc | microsoft_outlook_2013_rt_service_pack_1 | — | — |
| msrc | microsoft_outlook_2013_service_pack_1 | — | — |
| msrc | microsoft_outlook_2016 | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_msrc6.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft Outlook Elevation of Privilege Vulnerability
vendor_msrc·2018-02-13·CVSS 6.5
CVE-2018-0850 [MEDIUM] Microsoft Outlook Elevation of Privilege Vulnerability
Microsoft Outlook Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists when Microsoft Outlook initiates processing of incoming messages without sufficient validation of the formatting of the messages. An attacker who successfully exploited the vulnerability could attempt to force Outlook to load a local or remote message store (over SMB).
To exploit the vulnerability, the attacker could send a specially crafted email to a victim. Outlook would then attempt to open a pre-configured message store contained in the email upon receipt of the email.
This update addresses the vulnerability by ensuring Office fully validates incoming email formatting before processing message content.
FAQ: I am being offered this update for software that is not specifi
GHSA
GHSA-fgf4-56m5-8934: Microsoft Outlook 2007, Microsoft Outlook 2010, Microsoft Outlook 2013, Microsoft Outlook 2016, and Microsoft Office 2016 Click-to-Run allow an elevat
ghsa_unreviewed·2022-05-13
CVE-2018-0850 [MEDIUM] GHSA-fgf4-56m5-8934: Microsoft Outlook 2007, Microsoft Outlook 2010, Microsoft Outlook 2013, Microsoft Outlook 2016, and Microsoft Office 2016 Click-to-Run allow an elevat
Microsoft Outlook 2007, Microsoft Outlook 2010, Microsoft Outlook 2013, Microsoft Outlook 2016, and Microsoft Office 2016 Click-to-Run allow an elevation of privilege vulnerability due to how the format of incoming message is validated, aka "Microsoft Outlook Elevation of Privilege Vulnerability".
No detection rules found.
No public exploits indexed.
Qualys
Olympics, Patch Tuesday & Meltdown/Spectre | Qualys
blogs_qualys·2018-02-16
Olympics, Patch Tuesday & Meltdown/Spectre | Qualys
This week offered a representative sampling of different corners of the cyber security world: The monthly Patch Tuesday, a brazen attack against the Olympics, new Meltdown and Spectre concerns, and a boost for Intel’s bug bounty program.
Oh, and the gargantuan Equifax data breach may have been even bigger than previously thought.
### Winter Olympics hack confirmed
The 2018 Winter Olympics in Pyeongchang, South Korea are in full swing, featuring the world’s best ice skaters, skiers, hockey players and snowboarders, and also attracting, unfortunately, malicious hackers.
Attackers’ goals seem to be to disrupt the games in a variety of ways by interfering with and disabling IT systems.
Officials confirmed that hackers disrupted the opening ceremony by knocking the Winter Olympics’ website
Qualys
Hackers Hit the Olympics, While Patch Tuesday and Meltdown / Spectre Keep IT Departments On Edge
blogs_qualys·2018-02-16
Hackers Hit the Olympics, While Patch Tuesday and Meltdown / Spectre Keep IT Departments On Edge
This week offered a representative sampling of different corners of the cyber security world: The monthly Patch Tuesday, a brazen attack against the Olympics, new Meltdown and Spectre concerns, and a boost for Intel’s bug bounty program.
Oh, and the gargantuan Equifax data breach may have been even bigger than previously thought.
## Winter Olympics hack confirmed
The 2018 Winter Olympics in Pyeongchang, South Korea are in full swing, featuring the world’s best ice skaters, skiers, hockey players and snowboarders, and also attracting, unfortunately, malicious hackers.
Attackers’ goals seem to be to disrupt the games in a variety of ways by interfering with and disabling IT systems.
Officials confirmed that hackers disrupted the opening ceremony by knocking the Winter Olympics’ website
Trendmicro
February Patch Tuesday Fixes Privilege Escalation Bugs
blogs_trendmicro·2018-02-14·CVSS 8.8
[HIGH] February Patch Tuesday Fixes Privilege Escalation Bugs
Exploits & Vulnerabilities
## February Patch Tuesday Fixes Privilege Escalation Bugs
Microsoft’s Patch Tuesday has fixes addressing 50 security issues in Windows, Office, SharePoint, Internet Explorer, Edge, and ChakraCore JavaScript engine, as well as additional patches for the notorious Meltdown and Spectre vulnerabilities.
By: Trend Micro 2018/02/14 Read time: ( words)
Save to Folio
Microsoft’s Patch Tuesday for February has a bevy of fixes addressing 50 security issues in Windows, Office (including Office Services and Web Apps), SharePoint, Internet Explorer, Edge, and ChakraCore JavaScript engine, as well as additional patches for the notorious Meltdown and Spectre vulnerabilities. Of these, 14 were rated critical. Eight of these security flaws were disclosed through Trend Micro’
Trendmicro
February Patch Tuesday Fixes Privilege Escalation Bugs
blogs_trendmicro·2018-02-14·CVSS 8.8
[HIGH] February Patch Tuesday Fixes Privilege Escalation Bugs
Ausnutzung von Schwachstellen
## February Patch Tuesday Fixes Privilege Escalation Bugs
Microsoft’s Patch Tuesday has fixes addressing 50 security issues in Windows, Office, SharePoint, Internet Explorer, Edge, and ChakraCore JavaScript engine, as well as additional patches for the notorious Meltdown and Spectre vulnerabilities.
By: Trend Micro Feb 14, 2018 Read time: ( words)
Save to Folio
Microsoft’s Patch Tuesday for February has a bevy of fixes addressing 50 security issues in Windows, Office (including Office Services and Web Apps), SharePoint, Internet Explorer, Edge, and ChakraCore JavaScript engine, as well as additional patches for the notorious Meltdown and Spectre vulnerabilities. Of these, 14 were rated critical. Eight of these security flaws were disclosed through Trend M
Trendmicro
February Patch Tuesday Fixes Privilege Escalation Bugs
blogs_trendmicro·2018-02-14·CVSS 8.8
[HIGH] February Patch Tuesday Fixes Privilege Escalation Bugs
Exploits & Vulnerabilities
## February Patch Tuesday Fixes Privilege Escalation Bugs
Microsoft’s Patch Tuesday has fixes addressing 50 security issues in Windows, Office, SharePoint, Internet Explorer, Edge, and ChakraCore JavaScript engine, as well as additional patches for the notorious Meltdown and Spectre vulnerabilities.
By: Trend Micro Feb 14, 2018 Read time: ( words)
Save to Folio
Microsoft’s Patch Tuesday for February has a bevy of fixes addressing 50 security issues in Windows, Office (including Office Services and Web Apps), SharePoint, Internet Explorer, Edge, and ChakraCore JavaScript engine, as well as additional patches for the notorious Meltdown and Spectre vulnerabilities. Of these, 14 were rated critical. Eight of these security flaws were disclosed through Trend Micr
Trendmicro
February Patch Tuesday Fixes Privilege Escalation Bugs
blogs_trendmicro·2018-02-14·CVSS 8.8
[HIGH] February Patch Tuesday Fixes Privilege Escalation Bugs
Exploits & Vulnerabilities
# February Patch Tuesday Fixes Privilege Escalation Bugs
Microsoft’s Patch Tuesday has fixes addressing 50 security issues in Windows, Office, SharePoint, Internet Explorer, Edge, and ChakraCore JavaScript engine, as well as additional patches for the notorious Meltdown and Spectre vulnerabilities.
By: Trend Micro
2018/02/14
Read time: ( words)
Save to Folio
Microsoft’s Patch Tuesday for February has a bevy of fixes addressing 50 security issues in Windows, Office (including Office Services and Web Apps), SharePoint, Internet Explorer, Edge, and ChakraCore JavaScript engine, as well as additional patches for the notorious Meltdown and Spectre vulnerabilities. Of these, 14 were rated critical. Eight of these security flaws were disclosed through Trend Micro’
Trendmicro
February Patch Tuesday Fixes Privilege Escalation Bugs
blogs_trendmicro·2018-02-14·CVSS 8.8
[HIGH] February Patch Tuesday Fixes Privilege Escalation Bugs
Exploits y vulnerabilidades
## February Patch Tuesday Fixes Privilege Escalation Bugs
Microsoft’s Patch Tuesday has fixes addressing 50 security issues in Windows, Office, SharePoint, Internet Explorer, Edge, and ChakraCore JavaScript engine, as well as additional patches for the notorious Meltdown and Spectre vulnerabilities.
By: Trend Micro Feb 14, 2018 Read time: ( words)
Save to Folio
Microsoft’s Patch Tuesday for February has a bevy of fixes addressing 50 security issues in Windows, Office (including Office Services and Web Apps), SharePoint, Internet Explorer, Edge, and ChakraCore JavaScript engine, as well as additional patches for the notorious Meltdown and Spectre vulnerabilities. Of these, 14 were rated critical. Eight of these security flaws were disclosed through Trend Mic
Talos
Microsoft Patch Tuesday - February 2018
blogs_talos·2018-02-13·CVSS 3.1
[LOW] Microsoft Patch Tuesday - February 2018
Microsoft Patch Tuesday - February 2018
Today Microsoft has released its monthly set of security advisories for vulnerabilities that have been identified and addressed in various products. This month's advisory release addresses 54 new vulnerabilities with 14 of them rated critical, 38 of them rated important, and 2 of them rated Moderate. These vulnerabilities impact Outlook, Edge, Scripting Engine, App Container, Windows, and more.
## Critical VulnerabilitiesThis month, Microsoft is addressing 14 vulnerabilities that are rated "critical." Talos believes one of these are notable and require prompt attention, detailed below.
CVE-2018-0852 - Microsoft Outlook Memory Corruption Vulnerability
A remote code execution vulnerability has been identified in Microsoft Outlook when the software
Talos
Microsoft Patch Tuesday - February 2018
blogs_talos·2018-02-13·CVSS 3.1
[LOW] Microsoft Patch Tuesday - February 2018
## Microsoft Patch Tuesday - February 2018
Microsoft Patch Tuesday - February 2018
Today Microsoft has released its monthly set of security advisories for vulnerabilities that have been identified and addressed in various products. This month's advisory release addresses 54 new vulnerabilities with 14 of them rated critical, 38 of them rated important, and 2 of them rated Moderate. These vulnerabilities impact Outlook, Edge, Scripting Engine, App Container, Windows, and more.
## Critical Vulnerabilities This month, Microsoft is addressing 14 vulnerabilities that are rated "critical." Talos believes one of these are notable and require prompt attention, detailed below.
CVE-2018-0852 - Microsoft Outlook Memory Corruption Vulnerability
A remote code execution vulnerability has been ident
http://www.securityfocus.com/bid/102866http://www.securitytracker.com/id/1040382https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0850http://www.securityfocus.com/bid/102866http://www.securitytracker.com/id/1040382https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0850
2018-02-15
Published