PT-2018-9139 · Microsoft · Office 2016 Click-To-Run+2

Published

2018-03-13

·

Updated

2020-08-24

·

CVE-2018-0903

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Microsoft Access versions 2010 SP2 through 2016
Description: A remote code execution issue exists due to improper handling of objects in memory. An attacker could run arbitrary code in the context of the current user. If the user has administrative rights, the attacker could take control of the system, install programs, view or modify data, or create new accounts. Users with limited rights may be less affected. Exploitation requires a user to open a specially crafted file with an affected version of Microsoft Access.
Recommendations: For Microsoft Access 2010 SP2, update to a version that properly handles objects in memory to prevent exploitation. For Microsoft Access 2013 SP1, apply the necessary patch to fix the remote code execution issue. For Microsoft Access 2016, consider disabling the handling of specially crafted files until a patch is available. For Microsoft Office 2016 Click-to-Run, restrict access to specially crafted files to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2018-0903

Affected Products

Access
Office 2016 Click-To-Run
Office Access