CVE-2018-1028

high

Description

A remote code execution vulnerability exists when the Office graphics component improperly handles specially crafted embedded fonts, aka "Microsoft Office Graphics Remote Code Execution Vulnerability." This affects Word, Microsoft Office, Microsoft SharePoint, Excel, Microsoft SharePoint Server.

References

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-1028

http://www.securitytracker.com/id/1040654

http://www.securityfocus.com/bid/103641

Details

Source: Mitre, NVD

Published: 2018-04-12

Updated: 2018-05-21

Risk Information

CVSS v2

Base Score: 9.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Severity: High