PT-2018-2112 · Microsoft · Office 365 Proplus+2
Yonghui Han
·
Published
2018-12-11
·
Updated
2020-08-24
·
CVE-2018-8587
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Outlook versions prior to the fixed version
Office 365 ProPlus (affected versions not specified)
Microsoft Office (affected versions not specified)
Description
The issue is related to errors in the mechanisms for handling objects in memory. Exploitation of this issue may allow an attacker to execute arbitrary code with the privileges of the current user using specially crafted content. To exploit the issue, a user must open a specially crafted file with an affected version of Microsoft Outlook software. The Preview Pane is not an attack vector for this issue.
Recommendations
For Microsoft Outlook, update to a version that includes the fix for this issue.
For Office 365 ProPlus, apply the recommended configuration changes to minimize the risk of exploitation.
For Microsoft Office, consider restricting access to specially crafted files until a patch is available.
As a temporary workaround, consider disabling the handling of specially crafted files in Microsoft Outlook until a patch is available.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Office
Outlook
Office 365 Proplus