cbcvebase.
CVE-2018-1026
published 2018-04-12

CVE-2018-1026: A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka "Microsoft Office…

PriorityP260high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
42.24%
98.6th percentile
A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka "Microsoft Office Remote Code Execution Vulnerability." This affects Microsoft Office. This CVE ID is unique from CVE-2018-1030.

Affected

14 ranges
VendorProductVersion rangeFixed in
microsoftmicrosoft_office
microsoftmicrosoft_office
microsoftmicrosoft_office
microsoftmicrosoft_office
microsoftmicrosoft_office
microsoftmicrosoft_office
microsoftmicrosoft_office
microsoftoffice
microsoftoffice
msrcmicrosoft_office_2013_rt_service_pack_1
msrcmicrosoft_office_2013_service_pack_1
msrcmicrosoft_office_2016
msrcmicrosoft_office_2016_click-to-run_for_32-bit_editions
msrcmicrosoft_office_2016_click-to-run_for_64-bit_editions

Detection & IOCsextracted from sources · hover to see the quote

  • Exploitation requires a user to open a specially crafted file with an affected version of Microsoft Office; monitor for suspicious Office file opens originating from email attachments or web downloads
  • In email-based attack scenarios, the attacker sends a specially crafted file and convinces the user to open it; flag Office documents delivered via email from external/unknown senders
  • In web-based attack scenarios, attacker hosts or leverages a compromised website serving a specially crafted file; monitor for Office file downloads from untrusted or newly-registered domains
  • Successful exploitation results in arbitrary code running in the context of the current user; monitor for unexpected child processes spawned by Office applications (e.g., WINWORD.EXE, EXCEL.EXE) as a post-exploitation indicator
  • Root cause is improper handling of objects in memory within Microsoft Office; consider enabling Protected View and Attack Surface Reduction (ASR) rules targeting Office object handling
  • ·The update may apply broadly to shared components across multiple Office versions/products beyond those explicitly listed in the Affected Software table; ensure patching covers all installed Office products
  • ·CVE-2018-1026 is distinct from CVE-2018-1030, which is a separate Microsoft Office RCE vulnerability patched in the same cycle; ensure both CVEs are tracked independently
  • ·Microsoft assesses exploitation as 'More Likely' for both latest and older software releases; prioritize patching accordingly

CVSS provenance

nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.