CVE-2018-8246Sensitive Information Exposure in Microsoft Excel

Severity
5.5MEDIUMNVD
EPSS
25.5%
top 3.77%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 14
Latest updateMay 14

Description

An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka "Microsoft Excel Information Disclosure Vulnerability." This affects Microsoft Excel Viewer, Microsoft Office, Microsoft Excel.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

NVDmicrosoft/excel2010, 2013, 2016+2
NVDmicrosoft/office2010, 2016+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-hp3h-g8ww-jfhh: An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka "Microsoft Excel Information2022-05-14
CVEList
CVE-2018-8246: An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka "Microsoft Excel Information2018-06-14

📋Vendor Advisories

1
Microsoft
Microsoft Excel Information Disclosure Vulnerability2018-06-12
CVE-2018-8246 — Sensitive Information Exposure | cvebase