9.3

CVE-2018-0798

Warnung
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Office Memory Corruption Vulnerability".
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Office Version 2007 Update sp3
Microsoft ≫ Office Version 2010 Update sp2
Microsoft ≫ Office Version 2013 Update sp1
Microsoft ≫ Office Version 2016
Microsoft ≫ Office Version 2016 SwEdition click-to-run
Microsoft ≫ Office Compatibility Pack Version - Update sp3
Microsoft ≫ Word Version 2007 Update sp3
Microsoft ≫ Word Version 2010 Update sp2
Microsoft ≫ Word Version 2013 Update sp1
Microsoft ≫ Word Version 2013 Update sp1 SwEdition rt
Microsoft ≫ Word Version 2016

03.11.2021: CISA Known Exploited Vulnerabilities (KEV) Catalog

Microsoft Office Memory Corruption Vulnerability

Schwachstelle

Microsoft Office contains a memory corruption vulnerability due to the way objects are handled in memory. Successful exploitation allows for remote code execution in the context of the current user. This vulnerability is known to be chained with CVE-2018-0802.

Beschreibung

Apply updates per vendor instructions.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 90.99% 0.998
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
NIST 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CISA-ADP 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

http://www.securitytracker.com/id/1040153
Third Party Advisory
Broken Link
VDB Entry
http://www.securityfocus.com/bid/102370
Third Party Advisory
Broken Link
VDB Entry
https://0patch.blogspot.com/2018/01/bringing-abandoned-equation-editor-back.html
Third Party Advisory
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0798
Patch
Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-0798
US Government Resource