PT-2018-2091 · Microsoft · Windows 7+10

Lin Wang

·

Published

2018-10-09

·

Updated

2020-08-24

·

CVE-2018-8432

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Graphics Components versions prior to the fixed version Windows 7 Windows Server 2019 Windows Server 2008 R2 Windows Server 2008 Microsoft Office Microsoft Office Word Viewer Office 365 ProPlus Microsoft Excel Viewer Microsoft PowerPoint Viewer
Description A remote code execution issue exists in the way Microsoft Graphics Components handle objects in memory. This allows an attacker to execute arbitrary code on a target system by opening a specially crafted file. The vulnerability is caused by a buffer overflow in memory.
Recommendations For Windows 7, apply the patch from the latest patchday to resolve the issue. For Windows Server 2019, Windows Server 2008 R2, and Windows Server 2008, apply the patch from the latest patchday to resolve the issue. For Microsoft Office, update to a version that includes the fix for this issue. For Microsoft Office Word Viewer, Microsoft Excel Viewer, and Microsoft PowerPoint Viewer, avoid opening specially crafted files until a patch is available. For Office 365 ProPlus, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to specially crafted files to minimize the risk of exploitation.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-00042
CVE-2018-8432

Affected Products

Excel Viewer
Graphics Components
Office
Office Word Viewer
Powerpoint Viewer
Office 365 Proplus
Windows
Windows 7
Windows Server 2008
Windows Server 2008 R2
Windows Server 2019