← Back

CVE-2018-8378

nvd nist
Published: Aug 15, 2018Modified: Jun 17, 2026

JSON object

Loading...
5.5
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Exploitability: 1.8 / Impact: 3.6
Source: NVD

Description

An information disclosure vulnerability exists when Microsoft Office software reads out of bound memory due to an uninitialized variable, which could disclose the contents of memory, aka "Microsoft Office Information Disclosure Vulnerability." This affects Word, Microsoft SharePoint Server, Microsoft Office Word Viewer, Microsoft Excel Viewer, Microsoft SharePoint, Microsoft Office.

Affected (14)

9 products
Excel Viewer
Office
Office Compatibility Pack
Office Web Apps
Office Word Viewer
Sharepoint Enterprise Server 2013
Sharepoint Enterprise Server 2016
Sharepoint Server
Word Automation Services
Configuration A
13 vulnerable
Vulnerable SoftwareAffected Versions
Version 2007 sp3
Microsoft
Version 2010 sp2
Version 2013 sp1
Version 2013 sp1
Version 2016
Version 2016
All versions
Microsoft
Version 2010 sp2
Version 2013 sp1
All versions
All versions
All versions
Version 2013 sp1
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Microsoft
Sharepoint Server
Version 2010 sp2

References (4)

Source: secure@microsoft.com
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.