CVE-2018-8504

HIGH

Description

A remote code execution vulnerability exists in Microsoft Word software when the software fails to properly handle objects in Protected View, aka "Microsoft Word Remote Code Execution Vulnerability." This affects Microsoft SharePoint Server, Office 365 ProPlus, Microsoft Office, Microsoft Word.

References

http://www.securityfocus.com/bid/105499

http://www.securitytracker.com/id/1041840

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8504

Details

Source: MITRE

Published: 2018-10-10

Updated: 2018-11-26

Type: CWE-19

Risk Information

CVSS v2.0

Base Score: 9.3

Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 8.6

Severity: HIGH

CVSS v3.0

Base Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 2.8

Severity: HIGH