CVE-2018-0852

Severity
8.8HIGH
EPSS
30.5%
top 3.29%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 15
Latest updateMay 13

Description

Microsoft Outlook 2007 SP3, Microsoft Outlook 2010 SP2, Microsoft Outlook 2013 SP1 and RT SP1, Microsoft Outlook 2016, and Microsoft Office 2016 Click-to-Run (C2R) allow a remote code execution vulnerability, due to how Outlook handles objects in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE is unique from CVE-2018-0851.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages3 packages

NVDmicrosoft/outlook2010, 2013, 2016+2
CVEListV5microsoft_corporation/microsoft_officeMicrosoft Outlook 2007 SP3, Microsoft Outlook 2010 SP2, Microsoft Outlook 2013 SP1 and RT SP1, Microsoft Outlook 2016, and Microsoft Office 2016 Click-to-Run (C2R).

Patches

🔴Vulnerability Details

2
GHSA
GHSA-2jhv-9q6m-gc8r: Microsoft Outlook 2007 SP3, Microsoft Outlook 2010 SP2, Microsoft Outlook 2013 SP1 and RT SP1, Microsoft Outlook 2016, and Microsoft Office 2016 Click2022-05-13
CVEList
CVE-2018-0852: Microsoft Outlook 2007 SP3, Microsoft Outlook 2010 SP2, Microsoft Outlook 2013 SP1 and RT SP1, Microsoft Outlook 2016, and Microsoft Office 2016 Click2018-02-15

📋Vendor Advisories

1
Microsoft
Microsoft Outlook Memory Corruption Vulnerability2018-02-13

🕵️Threat Intelligence

1
Talos
Microsoft Patch Tuesday - February 20182018-02-13