CVE-2018-8176

Severity
8.8HIGH
EPSS
36.4%
top 2.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 23
Latest updateMay 14

Description

A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly validate XML content, aka "Microsoft PowerPoint Remote Code Execution Vulnerability." This affects Microsoft Office.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

CVEListV5microsoft/microsoft_office2016 for Mac

Patches

🔴Vulnerability Details

2
GHSA
GHSA-j39f-3w23-66c2: A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly validate XML content, aka "Microsoft2022-05-14
CVEList
CVE-2018-8176: A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly validate XML content, aka "Microsoft2018-05-23

📋Vendor Advisories

1
Microsoft
Microsoft PowerPoint Remote Code Execution Vulnerability2018-05-08
CVE-2018-8176 (HIGH CVSS 8.8) | A remote code execution vulnerabili | cvebase.io