CVE-2018-0853

CWE-6654 documents4 sources
Severity
3.3LOW
EPSS
13.1%
top 5.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 15
Latest updateMay 13

Description

Microsoft Office 2010 SP2, Microsoft Office 2013 SP1 and RT SP1, Microsoft Office 2016, and Microsoft Office 2016 Click-to-Run (C2R) allow an information disclosure vulnerability, due to how Office initializes the affected variable, aka "Microsoft Office Information Disclosure Vulnerability".

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:NExploitability: 1.8 | Impact: 1.4

Affected Packages2 packages

NVDmicrosoft/office2010, 2013, 2016+2
CVEListV5microsoft_corporation/microsoft_officeMicrosoft Office 2010 SP2, Microsoft Office 2013 SP1 and RT SP1, Microsoft Office 2016, and Microsoft Office 2016 Click-to-Run (C2R).

Patches

🔴Vulnerability Details

2
GHSA
GHSA-p7x9-2gr9-qm7x: Microsoft Office 2010 SP2, Microsoft Office 2013 SP1 and RT SP1, Microsoft Office 2016, and Microsoft Office 2016 Click-to-Run (C2R) allow an informat2022-05-13
CVEList
CVE-2018-0853: Microsoft Office 2010 SP2, Microsoft Office 2013 SP1 and RT SP1, Microsoft Office 2016, and Microsoft Office 2016 Click-to-Run (C2R) allow an informat2018-02-15

📋Vendor Advisories

1
Microsoft
Microsoft Office Information Disclosure Vulnerability2018-02-13
CVE-2018-0853 (LOW CVSS 3.3) | Microsoft Office 2010 SP2 | cvebase.io