Jaanus Kääp

Pesquisador deClarified Security
#1542de 53,639
144.9CVSS total
Vulnerabilidades · 18
Média
5
Alta
13
PT-2018-9152
4.3
2018-03-13
Microsoft · Sharepoint Server · CVE-2018-0919
Name of the Vulnerable Software and Affected Versions: Microsoft Office versions 2010 SP2, 2013 SP1, and 2016 Microsoft Office 2016 Click-to-Run Microsoft Office 2016 for Mac Microsoft Office Web Apps versions 2010 SP2 and 2013 SP1 Microsoft SharePoint Enterprise Server versions 2013 SP1 and 2016 Microsoft SharePoint Server 2010 SP2 Microsoft Word versions 2010 SP2, 2013 SP1, and 2016 Description: An information disclosure issue exists due to how variables are initialized, allowing an attacker to view out of bound memory. This could disclose the contents of memory when Microsoft Office software reads out of bound memory due to an uninitialized variable. Exploitation requires a user to open a specially crafted file with an affected version of Microsoft Office software. Recommendations: For Microsoft Office 2010 SP2, update to a newer version to mitigate the risk. For Microsoft Office 2013 SP1, update to a newer version to mitigate the risk. For Microsoft Office 2016, update to a newer version to mitigate the risk. For Microsoft Office 2016 Click-to-Run, update to a newer version to mitigate the risk. For Microsoft Office 2016 for Mac, update to a newer version to mitigate the risk. For Microsoft Office Web Apps 2010 SP2, update to a newer version to mitigate the risk. For Microsoft Office Web Apps 2013 SP1, update to a newer version to mitigate the risk. For Microsoft SharePoint Enterprise Server 2013 SP1, update to a newer version to mitigate the risk. For Microsoft SharePoint Enterprise Server 2016, update to a newer version to mitigate the risk. For Microsoft SharePoint Server 2010 SP2, update to a newer version to mitigate the risk. For Microsoft Word 2010 SP2, update to a newer version to mitigate the risk. For Microsoft Word 2013 SP1, update to a newer version to mitigate the risk. For Microsoft Word 2016, update to a newer version to mitigate the risk. As a temporary workaround, consider avoiding the use of uninitialized variables in Microsoft Office software until a patch is available.
PT-2017-2959
9.3
2017-09-12
Microsoft · Office Compatibility Pack · CVE-2017-8632
**Name of the Vulnerable Software and Affected Versions** Microsoft Office (affected versions not specified) Microsoft Excel (affected versions not specified) Microsoft Excel for Mac (affected versions not specified) Microsoft Office Web Apps (affected versions not specified) Microsoft Office Compatibility Pack (affected versions not specified) **Description** The issue is related to the incorrect handling of objects in memory by Microsoft Office software, including Microsoft Excel and Microsoft Excel for Mac, Microsoft Office Web Apps, and Microsoft Office Compatibility Pack. This can allow a remote attacker to gain privileges of the current user by using a specially crafted file. Exploitation requires a user to open the specially crafted file with an affected version of the software. **Recommendations** For Microsoft Office, update to a version that properly handles objects in memory to prevent exploitation. For Microsoft Excel, consider avoiding the use of specially crafted files until a patch is available. For Microsoft Excel for Mac, restrict access to potentially vulnerable files to minimize the risk of exploitation. For Microsoft Office Web Apps, avoid using the software to open untrusted files until the issue is resolved. For Microsoft Office Compatibility Pack, consider disabling the pack until a fixed version is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.