CVE-2018-8160

Severity
6.5MEDIUM
EPSS
23.0%
top 4.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 9
Latest updateMay 14

Description

An information disclosure vulnerability exists in Outlook when a message is opened, aka "Microsoft Outlook Information Disclosure Vulnerability." This affects Word, Microsoft Office.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages5 packages

CVEListV5microsoft/wordAutomation Services on Microsoft SharePoint Server 2010 Service Pack 2
CVEListV5microsoft/microsoft_office4 versions+3

Patches

🔴Vulnerability Details

2
GHSA
GHSA-m8vr-j794-rf47: An information disclosure vulnerability exists in Outlook when a message is opened, aka "Microsoft Outlook Information Disclosure Vulnerability2022-05-14
CVEList
CVE-2018-8160: An information disclosure vulnerability exists in Outlook when a message is opened, aka "Microsoft Outlook Information Disclosure Vulnerability2018-05-09

📋Vendor Advisories

1
Microsoft
Microsoft Outlook Information Disclosure Vulnerability2018-05-08