cbcvebase.
CVE-2018-8376
published 2018-08-15

CVE-2018-8376: A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle objects in memory, aka "Microsoft…

PriorityP261high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
18.15%
96.9th percentile
A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle objects in memory, aka "Microsoft PowerPoint Remote Code Execution Vulnerability." This affects Microsoft PowerPoint.

Affected

4 ranges
VendorProductVersion rangeFixed in
microsoftmicrosoft_powerpoint
microsoftmicrosoft_powerpoint
microsoftpowerpoint
msrcmicrosoft_powerpoint_2010_service_pack_2

Detection & IOCsextracted from sources · hover to see the quote

  • Attack vector requires a user to open a specially crafted PowerPoint file; the Preview Pane is explicitly NOT an attack vector for this vulnerability
  • In email-based attacks, the attacker sends a specially crafted PowerPoint file as an attachment and socially engineers the user to open it
  • In web-based attacks, the attacker hosts or compromises a website serving a specially crafted PowerPoint file; monitor for PowerPoint files downloaded from untrusted web sources
  • Note that the Preview Pane is not an attack vector — exploitation requires the file to be fully opened, which can help scope detection to file-open events in PowerPoint
  • ·Exploit status at time of advisory: not publicly disclosed and not exploited in the wild, but rated 'Exploitation More Likely' for older software releases — prioritise patching older Office installs

CVSS provenance

nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.