CVE-2018-8176
published 2018-05-23CVE-2018-8176: A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly validate XML content, aka "Microsoft…
PriorityP260high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
22.08%
97.4th percentile
A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly validate XML content, aka "Microsoft PowerPoint Remote Code Execution Vulnerability." This affects Microsoft Office.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_office | — | — |
| microsoft | office_for_mac | — | — |
| msrc | microsoft_office_2016_for_mac | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Vulnerability is triggered only after the user opens a specially crafted PowerPoint file AND moves their mouse over a specific location on the page — mouse-hover interaction is required to trigger the exploit ↗
- →The Preview Pane in Windows Explorer / Outlook is NOT an attack vector; detection/triage should focus on files that are fully opened by the PowerPoint application ↗
- →Root cause is improper validation of XML content inside PowerPoint files; inspect PPTX/PPSX/ODP-style XML streams for malformed or unexpected XML structures as a detection signal ↗
- →Attack delivery vectors are email attachment (user convinced to open file) or web-hosted specially crafted file — monitor for PowerPoint files downloaded from the web or received via email that trigger unusual child processes ↗
- ·Exploit status is 'Publicly Disclosed: Yes' but 'Exploited: No' with 'Exploitation Unlikely' for the latest software release — prioritize patching but in-the-wild exploitation has not been confirmed as of the advisory ↗
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-j39f-3w23-66c2: A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly validate XML content, aka "Microsoft
ghsa_unreviewed·2022-05-14
CVE-2018-8176 [HIGH] CWE-20 GHSA-j39f-3w23-66c2: A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly validate XML content, aka "Microsoft
A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly validate XML content, aka "Microsoft PowerPoint Remote Code Execution Vulnerability." This affects Microsoft Office.
Microsoft
Microsoft PowerPoint Remote Code Execution Vulnerability
vendor_msrc·2018-05-08·CVSS 8.8
CVE-2018-8176 [HIGH] Microsoft PowerPoint Remote Code Execution Vulnerability
Microsoft PowerPoint Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly validate XML content. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
Exploitation of the vulnerability requires that a user open a specially crafted fi
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/104184http://www.securitytracker.com/id/1040937https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8176http://www.securityfocus.com/bid/104184http://www.securitytracker.com/id/1040937https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8176
2018-05-23
Published