PT-2018-1314 · Microsoft · Office Excel

Omair

·

Published

2018-05-08

·

Updated

2020-08-24

·

CVE-2018-8162

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Excel (affected versions not specified)
Description The issue is caused by an out-of-bounds access in memory, allowing a remote attacker to execute arbitrary code using a specially crafted XLS file. Exploitation of the vulnerability requires a user to open the malicious file with an affected version of Microsoft Excel. If successfully exploited, an attacker could run arbitrary code in the context of the current user, potentially taking control of the affected system, installing programs, viewing, changing, or deleting data, or creating new accounts with full user rights.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2018-00812
CVE-2018-8162
ZDI-18-432

Affected Products

Office Excel