Security Updates for Microsoft Word Products (July 2018)

high Nessus Plugin ID 110994

Synopsis

The Microsoft Word Products are missing a security update.

Description

The Microsoft Word Products are missing a security update.
It is, therefore, affected by the following vulnerability :

- A tampering vulnerability exists when Microsoft Outlook does not properly handle specific attachment types when rendering HTML emails. An attacker could exploit the vulnerability by sending a specially crafted email and attachment to a victim, or by hosting a malicious .eml file on a web server. The attacker who successfully exploited the vulnerability could then embed untrusted TrueType fonts in the body of an email. This behavior could be combined with other exploits to further compromise a user's system. The security update addresses the vulnerability by correcting how Microsoft Outlook handles attachments. (CVE-2018-8310)

Solution

Microsoft has released the following security updates to address this issue:
-KB4022218
-KB4022224
-KB4022202

See Also

http://www.nessus.org/u?38466f10

http://www.nessus.org/u?d5386f78

http://www.nessus.org/u?c3c4a554

Plugin Details

Severity: High

ID: 110994

File Name: smb_nt_ms18_jul_word.nasl

Version: 1.6

Type: local

Agent: windows

Published: 7/10/2018

Updated: 11/4/2019

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.6

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N

CVSS Score Source: CVE-2018-8310

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:microsoft:word

Required KB Items: SMB/MS_Bulletin_Checks/Possible

Exploit Ease: No known exploits are available

Patch Publication Date: 7/10/2018

Vulnerability Publication Date: 7/10/2018

Reference Information

CVE: CVE-2018-8310

BID: 104615

MSFT: MS18-4022202, MS18-4022218, MS18-4022224

MSKB: 4022202, 4022218, 4022224