Security Updates for Microsoft Word Products (July 2018)
High Nessus Plugin ID 110994
SynopsisThe Microsoft Word Products are missing a security update.
DescriptionThe Microsoft Word Products are missing a security update.
It is, therefore, affected by the following vulnerability :
- A tampering vulnerability exists when Microsoft Outlook does not properly handle specific attachment types when rendering HTML emails. An attacker could exploit the vulnerability by sending a specially crafted email and attachment to a victim, or by hosting a malicious .eml file on a web server. The attacker who successfully exploited the vulnerability could then embed untrusted TrueType fonts in the body of an email. This behavior could be combined with other exploits to further compromise a user's system. The security update addresses the vulnerability by correcting how Microsoft Outlook handles attachments. (CVE-2018-8310)
SolutionMicrosoft has released the following security updates to address this issue: