cbcvebase.
CVE-2018-8502
published 2018-10-10

CVE-2018-8502: A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in Protected View, aka "Microsoft…

PriorityP260high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
19.79%
97.1th percentile
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in Protected View, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Excel.

Affected

37 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftexcel
microsoftexcel
microsoftexcel
microsoftmicrosoft_excel
microsoftmicrosoft_excel
microsoftmicrosoft_excel
microsoftmicrosoft_excel
microsoftmicrosoft_excel
microsoftmicrosoft_excel
microsoftmicrosoft_excel
microsoftmicrosoft_office
microsoftmicrosoft_office
microsoftmicrosoft_office
microsoftmicrosoft_office
microsoftmicrosoft_office
microsoftmicrosoft_office
microsoftmicrosoft_office
microsoftmicrosoft_office
microsoftmicrosoft_office
microsoftoffice
microsoftoffice
microsoftoffice
microsoftoffice
microsoftoffice
microsoftoffice

Detection & IOCsextracted from sources · hover to see the quote

  • Attack vector requires a user to open a specially crafted Microsoft Excel file; the Preview Pane is NOT an attack vector — only full file open triggers the vulnerability
  • The vulnerability is triggered specifically when Excel fails to handle objects in Protected View — monitor for Excel processes spawning child processes or executing code after opening files in Protected View
  • Preview Pane is confirmed NOT an attack vector; detections should focus on full document open events, not preview actions
  • Exploitation likelihood is rated 'More Likely' for both latest and older software releases — prioritize detection and patching across all supported Office versions including Office 365 ProPlus, Microsoft Office, and Microsoft Excel

CVSS provenance

nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.