PT-2018-2091 · Microsoft · Windows 7+10
Lin Wang
·
Published
2018-10-09
·
Updated
2020-08-24
·
CVE-2018-8432
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Graphics Components versions prior to the fixed version
Windows 7
Windows Server 2019
Windows Server 2008 R2
Windows Server 2008
Microsoft Office
Microsoft Office Word Viewer
Office 365 ProPlus
Microsoft Excel Viewer
Microsoft PowerPoint Viewer
Description
A remote code execution issue exists in the way Microsoft Graphics Components handle objects in memory. This allows an attacker to execute arbitrary code on a target system by opening a specially crafted file. The vulnerability is caused by a buffer overflow in memory.
Recommendations
For Windows 7, apply the patch from the latest patchday to resolve the issue.
For Windows Server 2019, Windows Server 2008 R2, and Windows Server 2008, apply the patch from the latest patchday to resolve the issue.
For Microsoft Office, update to a version that includes the fix for this issue.
For Microsoft Office Word Viewer, Microsoft Excel Viewer, and Microsoft PowerPoint Viewer, avoid opening specially crafted files until a patch is available.
For Office 365 ProPlus, update to a version that includes the fix for this issue.
As a temporary workaround, consider restricting access to specially crafted files to minimize the risk of exploitation.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Excel Viewer
Graphics Components
Office
Office Word Viewer
Powerpoint Viewer
Office 365 Proplus
Windows
Windows 7
Windows Server 2008
Windows Server 2008 R2
Windows Server 2019