cbcvebase.
CVE-2018-8247
published 2018-06-14

CVE-2018-8247: An elevation of privilege vulnerability exists when Office Web Apps Server 2013 and Office Online Server fail to properly handle web requests, aka "Microsoft…

PriorityP428medium5.4CVSS 3.0
AVNACLPRNUIRSUCLILAN
EPSS
3.18%
86.6th percentile
An elevation of privilege vulnerability exists when Office Web Apps Server 2013 and Office Online Server fail to properly handle web requests, aka "Microsoft Office Elevation of Privilege Vulnerability." This affects Microsoft Office, Microsoft Office Online Server. This CVE ID is unique from CVE-2018-8245.

Affected

4 ranges
VendorProductVersion rangeFixed in
microsoftoffice_online_server
microsoftoffice_web_apps
msrcmicrosoft_office_online_server_2016
msrcmicrosoft_office_web_apps_server_2013_service_pack_1

CVSS provenance

nvdv3.05.4MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
vendor_msrc5.4HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.