Security Updates for Microsoft Word Products (July 2018)

High Nessus Plugin ID 110994


The Microsoft Word Products are missing a security update.


The Microsoft Word Products are missing a security update.
It is, therefore, affected by the following vulnerability :

- A tampering vulnerability exists when Microsoft Outlook
does not properly handle specific attachment types when
rendering HTML emails. An attacker could exploit the
vulnerability by sending a specially crafted email and
attachment to a victim, or by hosting a malicious .eml
file on a web server. The attacker who successfully
exploited the vulnerability could then embed untrusted
TrueType fonts in the body of an email. This behavior
could be combined with other exploits to further
compromise a user's system. The security update
addresses the vulnerability by correcting how Microsoft
Outlook handles attachments. (CVE-2018-8310)


Microsoft has released the following security updates to address this issue:

See Also

Plugin Details

Severity: High

ID: 110994

File Name: smb_nt_ms18_jul_word.nasl

Version: 1.4

Type: local

Agent: windows

Published: 2018/07/10

Modified: 2018/09/17

Dependencies: 57033, 13855, 27524

Risk Information

Risk Factor: High

CVSS Score Source: manual

CVSS Score Rationale: Generated from microsoft security updates api.

CVSS v2.0

Base Score: 9.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

CVSS v3.0

Base Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Vulnerability Information

CPE: cpe:/a:microsoft:word

Patch Publication Date: 2018/07/10

Vulnerability Publication Date: 2018/07/10

Reference Information

CVE: CVE-2018-8310

BID: 104615

MSKB: 4022218, 4022224, 4022202

MSFT: MS18-4022218, MS18-4022224, MS18-4022202