KLA11386
Multiple vulnerabilities in Microsoft Office
Обновлено: 26/06/2019
Дата обнаружения
11/12/2018
Уровень угрозы
High
Описание

Multiple vulnerabilities were found in Microsoft Office. Malicious users can exploit these vulnerabilities to execute arbitrary code, gain privileges, obtain sensitive information, spoof user interface.

Below is a complete list of vulnerabilities:

  1. A remote code execution vulnerability in Microsoft Excel can be exploited remotely via specially crafted file to execute arbitrary code.
  2. An elevation of privilege vulnerability in Microsoft SharePoint Server can be exploited remotely via specially crafted authentication to gain privileges.
  3. An information disclosure vulnerability in Microsoft Excel can be exploited remotely to obtain sensitive information.
  4. An information disclosure vulnerability in Microsoft SharePoint can be exploited remotely to obtain sensitive information.
  5. A remote code execution vulnerability in Microsoft Outlook can be exploited remotely via specially crafted file to execute arbitrary code.
  6. A remote code execution vulnerability in Microsoft PowerPoint can be exploited remotely via specially crafted file to execute arbitrary code.
  7. A cross-site-scripting (XSS) vulnerability Microsoft Office SharePoint can be exploited remotely via specially crafted web-page to spoof user interface.
  8. An information disclosure vulnerability in Microsoft Excel can be exploited remotely via specially crafted file to obtain sensitive information.
Пораженные продукты

Microsoft Excel 2016 (32-bit edition)
Microsoft Excel 2016 (64-bit edition)
Office 365 ProPlus for 32-bit Systems
Microsoft Office 2010 Service Pack 2 (64-bit editions)
Microsoft Office Compatibility Pack Service Pack 3
Microsoft Office 2019 for 64-bit editions
Microsoft Excel 2013 Service Pack 1 (64-bit editions)
Microsoft Office 2010 Service Pack 2 (32-bit editions)
Microsoft Excel 2013 Service Pack 1 (32-bit editions)
Microsoft Office 2019 for Mac
Microsoft Excel 2010 Service Pack 2 (64-bit editions)
Microsoft Excel 2010 Service Pack 2 (32-bit editions)
Microsoft Office 2016 for Mac
Microsoft Office 2019 for 32-bit editions
Office 365 ProPlus for 64-bit Systems
Microsoft Excel 2013 RT Service Pack 1
Microsoft SharePoint Enterprise Server 2013 Service Pack 1
Microsoft SharePoint Enterprise Server 2016
Microsoft SharePoint Server 2010 Service Pack 2
Microsoft SharePoint Foundation 2010 Service Pack 2
Microsoft Outlook 2010 Service Pack 2 (64-bit editions)
Microsoft Outlook 2016 (64-bit edition)
Microsoft Outlook 2013 Service Pack 1 (64-bit editions)
Microsoft Outlook 2010 Service Pack 2 (32-bit editions)
Microsoft Outlook 2016 (32-bit edition)
Microsoft Outlook 2013 RT Service Pack 1
Microsoft Outlook 2013 Service Pack 1 (32-bit editions)
Microsoft PowerPoint 2013 Service Pack 1 (32-bit editions)
Microsoft PowerPoint 2016 (32-bit edition)
Microsoft Office Web Apps 2013 Service Pack 1
Office Online Server
Microsoft PowerPoint Viewer
Microsoft Office Web Apps 2010 Service Pack 2
Microsoft SharePoint Server 2013 Service Pack 1
Microsoft PowerPoint 2016 (64-bit edition)
Microsoft PowerPoint 2010 Service Pack 2 (32-bit editions)
Microsoft SharePoint Server 2019
Microsoft PowerPoint 2013 Service Pack 1 (64-bit editions)
Microsoft PowerPoint 2013 RT Service Pack 1
Microsoft PowerPoint 2010 Service Pack 2 (64-bit editions)
Excel Services
Microsoft Excel Viewer 2007 Service Pack 3

Решение

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Первичный источник обнаружения
CVE-2018-8597
CVE-2018-8635
CVE-2018-8598
CVE-2018-8636
CVE-2018-8580
CVE-2018-8587
CVE-2018-8628
CVE-2018-8650
CVE-2018-8627
Оказываемое влияние
?
ACE 
[?]

OSI 
[?]

PE 
[?]

SUI 
[?]
Связанные продукты
Microsoft Office
Microsoft Outlook
Microsoft Excel
CVE-IDS
CVE-2018-85977.8Critical
CVE-2018-86358.8Critical
CVE-2018-85984.7Warning
CVE-2018-86367.8Critical
CVE-2018-85804.3Warning
CVE-2018-85877.8Critical
CVE-2018-86287.8Critical
CVE-2018-86505.4High
CVE-2018-86275.5High
KB list

4011680
4461577
4461542
4461559
4461570
4461565
4461558
4461541
4461465
4461549
4461580
4461556
4461544
4461576
4461521
4011027
4461481
4461548
2597975
4461532
4011207
2965312
4092472
4461551
4461569
4461566

Microsoft official advisories
Microsoft Security Update Guide