cbcvebase.
CVE-2018-8598
published 2018-12-12

CVE-2018-8598: An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka "Microsoft Excel Information…

PriorityP273medium4.7CVSS 3.0
AVLACHPRNUIRSUCHINAN
ITWVulnCheck KEV
Exploited in the wild
EPSS
6.22%
92.7th percentile
An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka "Microsoft Excel Information Disclosure Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Excel. This CVE ID is unique from CVE-2018-8627.

Affected

34 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftexcel
microsoftexcel
microsoftexcel
microsoftexcel
microsoftexcel_viewer
microsoftmicrosoft_excel
microsoftmicrosoft_excel
microsoftmicrosoft_excel
microsoftmicrosoft_excel
microsoftmicrosoft_excel
microsoftmicrosoft_excel
microsoftmicrosoft_excel
microsoftmicrosoft_excel_viewer
microsoftmicrosoft_office
microsoftmicrosoft_office
microsoftmicrosoft_office
microsoftmicrosoft_office
microsoftmicrosoft_office
microsoftmicrosoft_office
microsoftmicrosoft_office
microsoftoffice
microsoftoffice
microsoftoffice
microsoftoffice
microsoftoffice

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability is triggered by opening a specially crafted document file in Microsoft Excel; detection should focus on suspicious Office document opens followed by anomalous memory access patterns.
  • The vulnerability results in disclosure of uninitialized memory contents from Excel; monitor for Excel processes exhibiting out-of-bounds or uninitialized memory reads.
  • Exploitation requires the attacker to know the memory address where the object was created, suggesting a two-stage attack; look for follow-on exploitation attempts after an Excel document is opened.
  • ·CVE-2018-8598 is distinct from CVE-2018-8627, which is a related but separate Microsoft Excel information disclosure vulnerability; ensure detections and patches target the correct CVE.
  • ·As of the advisory, this vulnerability had NOT been publicly disclosed or exploited in the wild, reducing immediate urgency but not eliminating risk.
  • ·The fix changes how certain Excel functions handle objects in memory; unpatched Excel installations remain vulnerable to information disclosure via malicious documents.

CVSS provenance

nvdv3.04.7MEDIUMCVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.02.6LOWAV:N/AC:H/Au:N/C:P/I:N/A:N
vulncheck4.7MEDIUM
vendor_msrc4.7HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.