Security Updates for Microsoft Word Products (July 2018)

High Nessus Plugin ID 110994

Synopsis

The Microsoft Word Products are missing a security update.

Description

The Microsoft Word Products are missing a security update.
It is, therefore, affected by the following vulnerability :

- A tampering vulnerability exists when Microsoft Outlook does not properly handle specific attachment types when rendering HTML emails. An attacker could exploit the vulnerability by sending a specially crafted email and attachment to a victim, or by hosting a malicious .eml file on a web server. The attacker who successfully exploited the vulnerability could then embed untrusted TrueType fonts in the body of an email. This behavior could be combined with other exploits to further compromise a user's system. The security update addresses the vulnerability by correcting how Microsoft Outlook handles attachments. (CVE-2018-8310)

Solution

Microsoft has released the following security updates to address this issue:
-KB4022218
-KB4022224
-KB4022202

See Also

http://www.nessus.org/u?38466f10

http://www.nessus.org/u?d5386f78

http://www.nessus.org/u?c3c4a554

Plugin Details

Severity: High

ID: 110994

File Name: smb_nt_ms18_jul_word.nasl

Version: 1.4

Type: local

Agent: windows

Published: 2018/07/10

Modified: 2018/09/17

Dependencies: 57033, 27524, 13855

Risk Information

Risk Factor: High

CVSS Score Source: manual

CVSS Score Rationale: Generated from microsoft security updates api.

CVSS v2.0

Base Score: 9.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

CVSS v3.0

Base Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Vulnerability Information

CPE: cpe:/a:microsoft:word

Required KB Items: SMB/MS_Bulletin_Checks/Possible

Patch Publication Date: 2018/07/10

Vulnerability Publication Date: 2018/07/10

Reference Information

CVE: CVE-2018-8310

BID: 104615

MSKB: 4022218, 4022224, 4022202

MSFT: MS18-4022218, MS18-4022224, MS18-4022202