Synopsis
The Microsoft Office Products are affected by multiple vulnerabilities.
Description
The Microsoft Office Products are missing security updates.
It is, therefore, affected by multiple vulnerabilities :
  - An information disclosure vulnerability exists when     Microsoft Office improperly discloses the contents of     its memory. An attacker who exploited the vulnerability     could use the information to compromise the users     computer or data.  (CVE-2018-1007)
  - An information disclosure vulnerability exists when     Office renders Rich Text Format (RTF) email messages     containing OLE objects when a message is opened or     previewed. This vulnerability could potentially result     in the disclosure of sensitive information to a     malicious site.  (CVE-2018-0950)
  - A remote code execution vulnerability exists in     Microsoft Office software when the software fails to     properly handle objects in memory. An attacker who     successfully exploited the vulnerability could run     arbitrary code in the context of the current user. If     the current user is logged on with administrative user     rights, an attacker could take control of the affected     system. An attacker could then install programs; view,     change, or delete data; or create new accounts with full     user rights.  (CVE-2018-1026, CVE-2018-1030)
  - A remote code execution vulnerability exists when the     Office graphics component improperly handles specially     crafted embedded fonts. An attacker who successfully     exploited this vulnerability could take control of the     affected system. An attacker could then install     programs; view, change, or delete data; or create new     accounts with full user rights.  (CVE-2018-1028)
Solution
Microsoft has released the following security updates to address this issue:  
  -KB4018357
  -KB4011628
  -KB4018330
  -KB4018319
  -KB4018288
  -KB4018328
  -KB4018311
Plugin Details
File Name: smb_nt_ms18_apr_office.nasl
Agent: windows
Supported Sensors: Nessus Agent, Nessus
Risk Information
Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C
Vulnerability Information
CPE: cpe:/a:microsoft:office
Required KB Items: SMB/MS_Bulletin_Checks/Possible
Exploit Ease: No known exploits are available
Patch Publication Date: 4/10/2018
Vulnerability Publication Date: 4/10/2018
Reference Information
CVE: CVE-2018-0950, CVE-2018-1007, CVE-2018-1026, CVE-2018-1028, CVE-2018-1030
MSFT: MS18-4011628, MS18-4018288, MS18-4018311, MS18-4018319, MS18-4018328, MS18-4018330, MS18-4018357
MSKB: 4011628, 4018288, 4018311, 4018319, 4018328, 4018330, 4018357