PT-2018-1580 · Microsoft · Jet Database Engine+1

Honggang Ren

+1

·

Published

2018-05-08

·

Updated

2020-08-24

·

CVE-2018-8392

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft JET Database Engine versions prior to the fixed version
Description A buffer overflow vulnerability exists in the Microsoft JET Database Engine that could allow remote code execution on an affected system. This issue can be exploited by using a specially crafted Excel file, potentially allowing an attacker to execute arbitrary code. The estimated number of potentially affected devices worldwide is not specified.
Recommendations For versions prior to the fixed version, apply the patch provided by Microsoft to resolve the issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2018-01137
CVE-2018-8392
ZDI-18-1049
ZDI-18-1050

Affected Products

Jet Database Engine
Windows