CVE-2018-8163Sensitive Information Exposure in Microsoft Excel

Severity
5.5MEDIUMNVD
EPSS
28.9%
top 3.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 9
Latest updateMay 14

Description

An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka "Microsoft Excel Information Disclosure Vulnerability." This affects Microsoft Office, Microsoft Excel.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

NVDmicrosoft/excel2010, 2013, 2016+2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-3jcj-hgr2-f986: An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka "Microsoft Excel Information2022-05-14
CVEList
CVE-2018-8163: An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka "Microsoft Excel Information2018-05-09

📋Vendor Advisories

1
Microsoft
Microsoft Excel Information Disclosure Vulnerability2018-05-08

💬Community

1
Bugzilla
CVE-2018-10894 keycloak: auth permitted with expired certs in SAML client2018-07-09
CVE-2018-8163 — Sensitive Information Exposure | cvebase