Microsoft Office 2007 SP2, Microsoft Office Word Viewer, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1 and RT SP1, Microsoft Office 2016, and Microsoft Office 2016 Click-to-Run (C2R) allow a remote code execution vulnerability, due to how Office handles objects in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE is unique from CVE-2018-0852.
2018-02-15T02:29:03.093
2024-11-21T03:39:05.503
Modified
CVSSv3.0: 8.8 (HIGH)
AV:N/AC:M/Au:N/C:C/I:C/A:C
8.6
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | microsoft | office | 2007 | Yes |
Application | microsoft | office | 2016 | Yes |
Application | microsoft | office | 2016 | Yes |
Application | microsoft | office_word_viewer | - | Yes |
Application | microsoft | outlook | 2010 | Yes |
Application | microsoft | outlook | 2013 | Yes |
Application | microsoft | outlook | 2013 | Yes |
Application | microsoft | outlook | 2016 | Yes |