cbcvebase.
CVE-2018-8502
published 2018-10-10

CVE-2018-8502: A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in Protected View, aka "Microsoft…

PriorityP260high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
20.46%
97.4th percentile
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in Protected View, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Excel.

Affected

37 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftexcel——
microsoftexcel——
microsoftexcel——
microsoftmicrosoft_excel——
microsoftmicrosoft_excel——
microsoftmicrosoft_excel——
microsoftmicrosoft_excel——
microsoftmicrosoft_excel——
microsoftmicrosoft_excel——
microsoftmicrosoft_excel——
microsoftmicrosoft_office——
microsoftmicrosoft_office——
microsoftmicrosoft_office——
microsoftmicrosoft_office——
microsoftmicrosoft_office——
microsoftmicrosoft_office——
microsoftmicrosoft_office——
microsoftmicrosoft_office——
microsoftmicrosoft_office——
microsoftoffice——
microsoftoffice——
microsoftoffice——
microsoftoffice——
microsoftoffice——
microsoftoffice——

Detection & IOCsextracted from sources · hover to see the quote

  • →Attack vector requires a user to open a specially crafted Microsoft Excel file; the Preview Pane is NOT an attack vector — only full file open triggers the vulnerability ↗
  • →The vulnerability is triggered specifically when Excel fails to handle objects in Protected View — monitor for Excel processes spawning child processes or executing code after opening files in Protected View ↗
  • →Preview Pane is confirmed NOT an attack vector; detections should focus on full document open events, not preview actions ↗
  • →Exploitation likelihood is rated 'More Likely' for both latest and older software releases — prioritize detection and patching across all supported Office versions including Office 365 ProPlus, Microsoft Office, and Microsoft Excel ↗

CVSS provenance

nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.