cbcvebase.
CVE-2018-8310
published 2018-07-11

CVE-2018-8310: A tampering vulnerability exists when Microsoft Outlook does not properly handle specific attachment types when rendering HTML emails, aka "Microsoft Office…

PriorityP341high7.5CVSS 3.0
AVNACLPRNUINSUCNIHAN
EPSS
5.36%
91.7th percentile
A tampering vulnerability exists when Microsoft Outlook does not properly handle specific attachment types when rendering HTML emails, aka "Microsoft Office Tampering Vulnerability." This affects Microsoft Word, Microsoft Office.

Affected

23 ranges
VendorProductVersion rangeFixed in
microsoftmicrosoft_office
microsoftmicrosoft_office
microsoftmicrosoft_office
microsoftmicrosoft_office
microsoftmicrosoft_word
microsoftmicrosoft_word
microsoftmicrosoft_word
microsoftmicrosoft_word
microsoftmicrosoft_word
microsoftmicrosoft_word
microsoftmicrosoft_word
microsoftoffice
microsoftoffice
microsoftword
microsoftword
microsoftword
msrcmicrosoft_office_2010_service_pack_2
msrcmicrosoft_office_2016_click-to-run_for_32-bit_editions
msrcmicrosoft_office_2016_click-to-run_for_64-bit_editions
msrcmicrosoft_word_2010_service_pack_2
msrcmicrosoft_word_2013_rt_service_pack_1
msrcmicrosoft_word_2013_service_pack_1
msrcmicrosoft_word_2016

CVSS provenance

nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vendor_msrc7.5LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.