Kaspersky ID:
KLA11386
Date de la détection:
12/11/2018
Mis à jour:
01/28/2026

Description

Multiple vulnerabilities were found in Microsoft Office. Malicious users can exploit these vulnerabilities to execute arbitrary code, gain privileges, obtain sensitive information, spoof user interface.

Below is a complete list of vulnerabilities:

  1. A remote code execution vulnerability in Microsoft Excel can be exploited remotely via specially crafted file to execute arbitrary code.
  2. An elevation of privilege vulnerability in Microsoft SharePoint Server can be exploited remotely via specially crafted authentication to gain privileges.
  3. An information disclosure vulnerability in Microsoft Excel can be exploited remotely to obtain sensitive information.
  4. An information disclosure vulnerability in Microsoft SharePoint can be exploited remotely to obtain sensitive information.
  5. A remote code execution vulnerability in Microsoft Outlook can be exploited remotely via specially crafted file to execute arbitrary code.
  6. A remote code execution vulnerability in Microsoft PowerPoint can be exploited remotely via specially crafted file to execute arbitrary code.
  7. A cross-site-scripting (XSS) vulnerability Microsoft Office SharePoint can be exploited remotely via specially crafted web-page to spoof user interface.
  8. An information disclosure vulnerability in Microsoft Excel can be exploited remotely via specially crafted file to obtain sensitive information.

Fiches de renseignement originales

Exploitation

Public exploits exist for this vulnerability.

Malware exists for this vulnerability. Usually such malware is classified as Exploit. More details.

Produits associés

Liste CVE

  • CVE-2018-8597
    critical
  • CVE-2018-8635
    critical
  • CVE-2018-8598
    warning
  • CVE-2018-8636
    critical
  • CVE-2018-8580
    warning
  • CVE-2018-8587
    critical
  • CVE-2018-8628
    critical
  • CVE-2018-8650
    high
  • CVE-2018-8627
    high

Liste KB

En savoir plus

Découvrez les statistiques de la propagation des vulnérabilités dans votre région statistics.securelist.com

Vous avez trouvé une inexactitude dans la description de cette vulnérabilité ? Faites-le nous savoir !
Kaspersky IT Security Calculator:
Calculez le profil de sécurité de votre entreprise
Apprendre encore plus
Kaspersky!
Votre vie en ligne mérite une protection complète!
Apprendre encore plus
Do you want to save your changes?
Your message has been sent successfully.