CVE-2018-8161

Description

A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka Microsoft Office Remote Code Execution Vulnerability. This affects Microsoft Word, Word, Microsoft Office, Microsoft SharePoint. This CVE ID is unique from CVE-2018-8157, CVE-2018-8158.

Risk Information

Base Score
7.8
MODERATE
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
32.436

Associated Vulnerability

VulnerabilityOS Platform
Microsoft SharePoint Elevation of Privilege Vulnerability for Microsoft SharePoint Enterprise Server 2016 (KB4018381)Windows
Microsoft Outlook Information Disclosure Vulnerability for Microsoft Web Applications (KB4022142)Windows
Microsoft Office Remote Code Execution Vulnerability for Microsoft Word 2010 (KB4022141) 64-Bit EditionWindows
Microsoft Office Remote Code Execution Vulnerability for Microsoft Word 2010 (KB4022141) 32-Bit EditionWindows
Microsoft Outlook Information Disclosure Vulnerability for Microsoft SharePoint Server 2010 (KB4022135)Windows
Microsoft Office Remote Code Execution Vulnerability for Microsoft Word 2013 (KB4018396) 64-Bit EditionWindows
Microsoft Office Remote Code Execution Vulnerability for Microsoft Word 2013 (KB4018396) 32-Bit EditionWindows
Microsoft Office Remote Code Execution Vulnerability for Microsoft Office Web Apps Server 2013 (KB4018393)Windows
Microsoft Office Remote Code Execution Vulnerability for Microsoft SharePoint Enterprise Server 2013 (KB4018388)Windows
Microsoft Office Remote Code Execution Vulnerability for Microsoft Office 2010 (KB4022139) 32-Bit EditionWindows
Microsoft Office Remote Code Execution Vulnerability for Microsoft Office 2010 (KB4022139) 64-Bit EditionWindows
Microsoft Office Remote Code Execution Vulnerability for Microsoft Word 2016 (KB4018383) 32-Bit EditionWindows
Microsoft Office Remote Code Execution Vulnerability for Microsoft Word 2016 (KB4018383) 64-Bit EditionWindows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-24613Security Update for Microsoft SharePoint Enterprise Server 2016 (KB4018381)
PATCH-24583Security Update for Microsoft Web Applications (KB4022142)
PATCH-24592Security Update for Microsoft Word 2010 (KB4022141) 32-Bit Edition
PATCH-24580Security Update for Microsoft SharePoint Server 2010 (KB4022135)
PATCH-24600Security Update for Microsoft Word 2013 (KB4018396) 64-Bit Edition
PATCH-24601Security Update for Microsoft Word 2013 (KB4018396) 32-Bit Edition
PATCH-24594Security Update for Microsoft SharePoint Enterprise Server 2013 (KB4018388)
PATCH-24586Security Update for Microsoft Office 2010 (KB4022139) 32-Bit Edition
PATCH-24589Security Update for Microsoft Office 2010 (KB4022139) 64-Bit Edition
PATCH-24611Security Update for Microsoft Word 2016 (KB4018383) 32-Bit Edition
PATCH-24612Security Update for Microsoft Word 2016 (KB4018383) 64-Bit Edition

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234