CVE-2018-0903

4 documents4 sources
Severity
7.8HIGH
EPSS
30.5%
top 3.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 14
Latest updateMay 13

Description

Microsoft Access 2010 SP2, Microsoft Access 2013 SP1, Microsoft Access 2016, and Microsoft Office 2016 Click-to-Run allow a remote code execution vulnerability due to how objects are handled in memory, aka "Microsoft Access Remote Code Execution Vulnerability".

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages3 packages

NVDmicrosoft/access2010, 2013, 2016+2
CVEListV5microsoft_corporation/microsoft_accessMicrosoft Access 2010 SP2, Microsoft Access 2013 SP1, Microsoft Access 2016, and Microsoft Office 2016 Click-to-Run

Patches

🔴Vulnerability Details

2
GHSA
GHSA-mjgr-cmwp-6j8c: Microsoft Access 2010 SP2, Microsoft Access 2013 SP1, Microsoft Access 2016, and Microsoft Office 2016 Click-to-Run allow a remote code execution vuln2022-05-13
CVEList
CVE-2018-0903: Microsoft Access 2010 SP2, Microsoft Access 2013 SP1, Microsoft Access 2016, and Microsoft Office 2016 Click-to-Run allow a remote code execution vuln2018-03-14

📋Vendor Advisories

1
Microsoft
Microsoft Access Remote Code Execution Vulnerability2018-03-13
CVE-2018-0903 (HIGH CVSS 7.8) | Microsoft Access 2010 SP2 | cvebase.io