PT-2018-1314 · Microsoft · Office Excel
Omair
·
Published
2018-05-08
·
Updated
2020-08-24
·
CVE-2018-8162
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Excel (affected versions not specified)
Description
The issue is caused by an out-of-bounds access in memory, allowing a remote attacker to execute arbitrary code using a specially crafted XLS file. Exploitation of the vulnerability requires a user to open the malicious file with an affected version of Microsoft Excel. If successfully exploited, an attacker could run arbitrary code in the context of the current user, potentially taking control of the affected system, installing programs, viewing, changing, or deleting data, or creating new accounts with full user rights.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Office Excel