Description
Multiple vulnerabilities have been found in Microsoft Office. Malicious users can exploit these vulnerabilities to execute arbitrary code, gain priveleges and obtain sensitive information. Below is a complete list of vulnerabilities:
- Remote code execution vulnerability in Microsoft Office software can be exploited via specially crafted file to execute arbitrary code;
- An elevation of privilege vulnerability in Microsoft Outlook software can be exploited via specially crafted file to gain priveleges;
- An elevation of privilege vulnerability in Microsoft SharePoint Server software can be exploited via specially crafted request to gain priveleges;
- An information disclosure vulnerability in Microsoft Office software can be exploited via specially crafted file to obtain sensitive information.
Original advisories
Exploitation
Malware exists for this vulnerability. Usually such malware is classified as Exploit. More details.
Related products
CVE list
- CVE-2018-0850 warning
- CVE-2018-0851 critical
- CVE-2018-0852 critical
- CVE-2018-0853 warning
- CVE-2018-0864 warning
- CVE-2018-0869 warning
- CVE-2018-0841 critical
KB list
Read more
Find out the statistics of the vulnerabilities spreading in your region on statistics.securelist.com
Found an inaccuracy in the description of this vulnerability? Let us know!