Security Updates for Microsoft Office Compatibility Products (June 2018)

Medium Nessus Plugin ID 110496

Synopsis

The Microsoft Office Compatibility Products are missing a security update.

Description

The Microsoft Office Compatibility Products are missing a security update. It is, therefore, affected by the following vulnerability :

- An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the users computer or data. (CVE-2018-8246)

Solution

Microsoft has released KB4022196 to address this issue.

See Also

http://www.nessus.org/u?7afc2d77

Plugin Details

Severity: Medium

ID: 110496

File Name: smb_nt_ms18_jun_office_compatibility.nasl

Version: 1.2

Type: local

Agent: windows

Published: 2018/06/12

Modified: 2018/06/14

Dependencies: 93232, 57033, 13855, 27524

Risk Information

Risk Factor: Medium

CVSSv2

Base Score: 4.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSSv3

Base Score: 4.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

Vulnerability Information

CPE: cpe:/a:microsoft:office_compatibility_pack

Required KB Items: SMB/MS_Bulletin_Checks/Possible

Patch Publication Date: 2018/06/12

Vulnerability Publication Date: 2018/06/12

Reference Information

CVE: CVE-2018-8246

MSKB: 4022196

MSFT: MS18-4022196

IAVA: 2018-A-0187