KLA11319
Multiple vulnerabilities in Microsoft Office
Updated: 09/12/2018
CVSS
?
8.8
Detect date
?
09/11/2018
Severity
?
Critical
Description

Multiple serious vulnerabilities were found in Microsoft Office. Malicious users can exploit these vulnerabilities to obtain sensitive information, execute arbitrary code, bypass security restrictions, gain privileges.

Below is a complete list of vulnerabilities:

  1. An information disclosure vulnerability in Microsoft Office SharePoint can be exploited remotely via specially crafted web request to obtain sensitive information.
  2. A remote code execution vulnerability in Microsoft Office Excel can be exploited remotely via specially crafted file to execute arbitrary code.
  3. A remote code execution vulnerability in Win32k Graphics can be exploited remotely via specially crafted embedded to execute arbitrary code.
  4. A remote code execution vulnerability in Microsoft Word can be exploited remotely via specially crafted PDF file to execute arbitrary code.
  5. An information disclosure vulnerability in Microsoft Excel can be exploited remotely to obtain sensitive information.
  6. A security feature bypass vulnerability in Lync can be exploited remotely via specially crafted messages to bypass security restrictions.
  7. An elevation of privilege vulnerability in Microsoft SharePoint can be exploited remotely via specially crafted web request to gain priveleges.
  8. An information disclosure vulnerability in Microsoft SharePoint can be exploited remotely via specially crafted web request to obtain sensitive information.
Affected products

Microsoft SharePoint Enterprise Server 2013 Service Pack 1
Microsoft SharePoint Server 2010 Service Pack 2
Microsoft SharePoint Enterprise Server 2016

Solution

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Original advisories

CVE-2018-8426
CVE-2018-8331
CVE-2018-8332
CVE-2018-8430
CVE-2018-8429
CVE-2018-8474
CVE-2018-8428
CVE-2018-8431

Impacts
?
ACE 
[?]

OSI 
[?]

SB 
[?]

PE 
[?]
Related products
Microsoft Office
CVE-IDS
?

CVE-2018-8332
CVE-2018-8426
CVE-2018-8331
CVE-2018-8430
CVE-2018-8429
CVE-2018-8474
CVE-2018-8428
CVE-2018-8431

KB list

4032246
4227175
4092447
4092466
4092459
4092479
4092460
4092470
4092467
4022207

Microsoft official advisories
Microsoft Security Update Guide