CVE-2018-1007
published 2018-04-12CVE-2018-1007: An information disclosure vulnerability exists when Microsoft Office improperly discloses the contents of its memory, aka "Microsoft Office Information…
PriorityP430medium5.3CVSS 3.0
AVNACHPRNUIRSUCHINAN
EPSS
6.75%
93.3th percentile
An information disclosure vulnerability exists when Microsoft Office improperly discloses the contents of its memory, aka "Microsoft Office Information Disclosure Vulnerability." This affects Microsoft Office. This CVE ID is unique from CVE-2018-0950.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_office | — | — |
| microsoft | microsoft_office | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | word | — | — |
| microsoft | word | — | — |
| microsoft | word | — | — |
| microsoft | word | — | — |
| msrc | microsoft_office_2016 | — | — |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.02.6LOWAV:N/AC:H/Au:N/C:P/I:N/A:N
vendor_msrc5.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fvrr-w793-x4hv: An information disclosure vulnerability exists when Office renders Rich Text Format (RTF) email messages containing OLE objects when a message is open
ghsa_unreviewed·2022-05-13·CVSS 5.3
CVE-2018-0950 [MEDIUM] GHSA-fvrr-w793-x4hv: An information disclosure vulnerability exists when Office renders Rich Text Format (RTF) email messages containing OLE objects when a message is open
An information disclosure vulnerability exists when Office renders Rich Text Format (RTF) email messages containing OLE objects when a message is opened or previewed, aka "Microsoft Office Information Disclosure Vulnerability." This affects Microsoft Word, Microsoft Office. This CVE ID is unique from CVE-2018-1007.
GHSA
GHSA-5qwh-c5rc-7f4v: An information disclosure vulnerability exists when Microsoft Office improperly discloses the contents of its memory, aka "Microsoft Office Informatio
ghsa_unreviewed·2022-05-13·CVSS 6.5
CVE-2018-1007 [MEDIUM] GHSA-5qwh-c5rc-7f4v: An information disclosure vulnerability exists when Microsoft Office improperly discloses the contents of its memory, aka "Microsoft Office Informatio
An information disclosure vulnerability exists when Microsoft Office improperly discloses the contents of its memory, aka "Microsoft Office Information Disclosure Vulnerability." This affects Microsoft Office. This CVE ID is unique from CVE-2018-0950.
Microsoft
Microsoft Office Information Disclosure Vulnerability
vendor_msrc·2018-04-10·CVSS 5.3
CVE-2018-1007 [MEDIUM] Microsoft Office Information Disclosure Vulnerability
Microsoft Office Information Disclosure Vulnerability
Description: An information disclosure vulnerability exists when Microsoft Office improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the user’s computer or data.
To exploit the vulnerability, an attacker could craft a special document file and then convince the user to open it. An attacker must know the memory address location where the object was created.
The update addresses the vulnerability by changing the way certain functions handle objects in memory.
Microsoft Office: Microsoft Office
Impact: Information Disclosure
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitat
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/103640http://www.securitytracker.com/id/1040654https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-1007http://www.securityfocus.com/bid/103640http://www.securitytracker.com/id/1040654https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-1007
2018-04-12
Published