KLA11319
Multiple vulnerabilities in Microsoft Office
Обновлено: 26/06/2019
Дата обнаружения
11/09/2018
Уровень угрозы
Critical
Описание

Multiple serious vulnerabilities were found in Microsoft Office. Malicious users can exploit these vulnerabilities to obtain sensitive information, execute arbitrary code, bypass security restrictions, gain privileges. Below is a complete list of vulnerabilities:

  1. An information disclosure vulnerability in Microsoft Office SharePoint can be exploited remotely via specially crafted web request to obtain sensitive information.
  2. A remote code execution vulnerability in Microsoft Office Excel can be exploited remotely via specially crafted file to execute arbitrary code.
  3. A remote code execution vulnerability in Win32k Graphics can be exploited remotely via specially crafted embedded to execute arbitrary code.
  4. A remote code execution vulnerability in Microsoft Word can be exploited remotely via specially crafted PDF file to execute arbitrary code.
  5. An information disclosure vulnerability in Microsoft Excel can be exploited remotely to obtain sensitive information.
  6. A security feature bypass vulnerability in Lync can be exploited remotely via specially crafted messages to bypass security restrictions.
  7. An elevation of privilege vulnerability in Microsoft SharePoint can be exploited remotely via specially crafted web request to gain priveleges.
  8. An information disclosure vulnerability in Microsoft SharePoint can be exploited remotely via specially crafted web request to obtain sensitive information.
Пораженные продукты

Microsoft SharePoint Enterprise Server 2013 Service Pack 1
Microsoft SharePoint Server 2010 Service Pack 2
Microsoft SharePoint Enterprise Server 2016

Решение

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Первичный источник обнаружения
CVE-2018-8426
CVE-2018-8331
CVE-2018-8332
CVE-2018-8430
CVE-2018-8429
CVE-2018-8474
CVE-2018-8428
CVE-2018-8431
Оказываемое влияние
?
ACE 
[?]

OSI 
[?]

SB 
[?]

PE 
[?]
Связанные продукты
Microsoft Office
CVE-IDS
CVE-2018-83328.8Critical
CVE-2018-84265.4High
CVE-2018-83317.8Critical
CVE-2018-84307.8Critical
CVE-2018-84295.5High
CVE-2018-84747.5Critical
CVE-2018-84285.4High
CVE-2018-84315.4High
KB list

4457128
4457144
4457145
4032246
4227175
4092447
4092466
4092459
4092479
4092460
4092470
4092467
4022207

Microsoft official advisories
Microsoft Security Update Guide