Kaspersky ID:
KLA11267
Detekováno:
06/12/2018
Aktualizováno:
01/22/2024

Popis

Multiple serious vulnerabilities have been found in Microsoft Office. Malicious users can exploit these vulnerabilities to gain privileges, obtain sensitive information or execute arbitrary code.

Below is a complete list of vulnerabilities:

  1. An incorrect handling of requests in Microsoft SharePoint Server can be exploited remotely via a specially designed request to gain privileges;
  2. Multiple improper handling of objects in memory vulnerabilities in Microsoft Excel can be exploited locally via a specially designed document file to execute arbitrary code or obtain sensitive information;
  3. An incorrect handling of requests in Office Web Apps Server 2013 and Office Online Server can be exploited remotely via a specially designed request to gain privileges;
  4. An incorrect OLE objects instantiation in Microsoft Publisher can be exploited remotely via a specially designed request to gain privileges;
  5. An improper validation of attachment headers in Microsoft Outlook can be exploited remotely via a specially designed e-main message to gain privileges.

Oficiální doporučení

Vykořisťování

Malware exists for this vulnerability. Usually such malware is classified as Exploit. More details.

Související produkty

seznam CVE

  • CVE-2018-8254
    warning
  • CVE-2018-8248
    critical
  • CVE-2018-8246
    warning
  • CVE-2018-8252
    warning
  • CVE-2018-8247
    high
  • CVE-2018-8245
    high
  • CVE-2018-8244
    warning

seznam KB

Zobrazit více

Zjistěte statistiky zranitelností šířících se ve vaší oblasti statistics.securelist.com

Našli jste v popisu této chyby zabezpečení nepřesnost? Dej nám vědět!
Kaspersky Next
Let’s go Next: redefine your business’s cybersecurity
Zjistěte více
Kaspersky Premium
Zjistěte více
Do you want to save your changes?
Your message has been sent successfully.