CVE-2018-8310
published 2018-07-11CVE-2018-8310: A tampering vulnerability exists when Microsoft Outlook does not properly handle specific attachment types when rendering HTML emails, aka "Microsoft Office…
PriorityP341high7.5CVSS 3.0
AVNACLPRNUINSUCNIHAN
EPSS
5.36%
91.7th percentile
A tampering vulnerability exists when Microsoft Outlook does not properly handle specific attachment types when rendering HTML emails, aka "Microsoft Office Tampering Vulnerability." This affects Microsoft Word, Microsoft Office.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_office | — | — |
| microsoft | microsoft_office | — | — |
| microsoft | microsoft_office | — | — |
| microsoft | microsoft_office | — | — |
| microsoft | microsoft_word | — | — |
| microsoft | microsoft_word | — | — |
| microsoft | microsoft_word | — | — |
| microsoft | microsoft_word | — | — |
| microsoft | microsoft_word | — | — |
| microsoft | microsoft_word | — | — |
| microsoft | microsoft_word | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | word | — | — |
| microsoft | word | — | — |
| microsoft | word | — | — |
| msrc | microsoft_office_2010_service_pack_2 | — | — |
| msrc | microsoft_office_2016_click-to-run_for_32-bit_editions | — | — |
| msrc | microsoft_office_2016_click-to-run_for_64-bit_editions | — | — |
| msrc | microsoft_word_2010_service_pack_2 | — | — |
| msrc | microsoft_word_2013_rt_service_pack_1 | — | — |
| msrc | microsoft_word_2013_service_pack_1 | — | — |
| msrc | microsoft_word_2016 | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vendor_msrc7.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r995-g428-fh4c: A tampering vulnerability exists when Microsoft Outlook does not properly handle specific attachment types when rendering HTML emails, aka "Microsoft
ghsa_unreviewed·2022-05-13
CVE-2018-8310 [HIGH] GHSA-r995-g428-fh4c: A tampering vulnerability exists when Microsoft Outlook does not properly handle specific attachment types when rendering HTML emails, aka "Microsoft
A tampering vulnerability exists when Microsoft Outlook does not properly handle specific attachment types when rendering HTML emails, aka "Microsoft Office Tampering Vulnerability." This affects Microsoft Word, Microsoft Office.
Microsoft
Microsoft Office Tampering Vulnerability
vendor_msrc·2018-07-10·CVSS 7.5
CVE-2018-8310 [HIGH] Microsoft Office Tampering Vulnerability
Microsoft Office Tampering Vulnerability
Description: A tampering vulnerability exists when Microsoft Outlook does not properly handle specific attachment types when rendering HTML emails. An attacker could exploit the vulnerability by sending a specially crafted email and attachment to a victim, or by hosting a malicious .eml file on a web server.
The attacker who successfully exploited the vulnerability could then embed untrusted TrueType fonts in the body of an email. This behavior could be combined with other exploits to further compromise a user's system.
The security update addresses the vulnerability by correcting how Microsoft Outlook handles attachments.
FAQ: I have Microsoft Word 2010 installed. Why am I not being offered the 4022200 update?
The 4022200 update only applies to s
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/104615http://www.securitytracker.com/id/1041274https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8310http://www.securityfocus.com/bid/104615http://www.securitytracker.com/id/1041274https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8310
2018-07-11
Published