cbcvebase.
CVE-2018-8501
published 2018-10-10

CVE-2018-8501: A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle objects in Protected View, aka…

PriorityP260high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
18.67%
97.0th percentile
A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle objects in Protected View, aka "Microsoft PowerPoint Remote Code Execution Vulnerability." This affects Office 365 ProPlus, PowerPoint Viewer, Microsoft Office, Microsoft PowerPoint.

Affected

40 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftmicrosoft_office
microsoftmicrosoft_office
microsoftmicrosoft_office
microsoftmicrosoft_office
microsoftmicrosoft_office
microsoftmicrosoft_office
microsoftmicrosoft_office
microsoftmicrosoft_office
microsoftmicrosoft_office
microsoftmicrosoft_powerpoint
microsoftmicrosoft_powerpoint
microsoftmicrosoft_powerpoint
microsoftmicrosoft_powerpoint
microsoftmicrosoft_powerpoint
microsoftmicrosoft_powerpoint
microsoftmicrosoft_powerpoint
microsoftoffice
microsoftoffice
microsoftoffice
microsoftoffice
microsoftoffice
microsoftoffice
microsoftpowerpoint
microsoftpowerpoint
microsoftpowerpoint

Detection & IOCsextracted from sources · hover to see the quote

  • Email-borne delivery is a primary attack scenario — monitor for PowerPoint file attachments (e.g., .ppt, .pptx, .ppsx) opened directly from email clients.
  • Web-based delivery is a secondary attack scenario — monitor for PowerPoint files downloaded from browsers and subsequently opened, particularly from compromised or attacker-controlled sites.
  • The vulnerability is triggered by improper handling of objects in Protected View — monitor for PowerPoint processes spawning unexpected child processes or executing code while Protected View is active.
  • Exploitation likelihood is rated 'More Likely' for both latest and older software releases — prioritize detection and patching across all supported Office versions.
  • ·Affected products span multiple Office SKUs and versions — ensure patch coverage includes Office 365 ProPlus (formerly Office 2016 C2R), PowerPoint Viewer, and standalone Microsoft Office/PowerPoint installs.

CVSS provenance

nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.