CVE-2018-8504

high

Description

A remote code execution vulnerability exists in Microsoft Word software when the software fails to properly handle objects in Protected View, aka "Microsoft Word Remote Code Execution Vulnerability." This affects Microsoft SharePoint Server, Office 365 ProPlus, Microsoft Office, Microsoft Word.

References

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8504

http://www.securitytracker.com/id/1041840

http://www.securityfocus.com/bid/105499

Details

Source: Mitre, NVD

Published: 2018-10-10

Updated: 2024-11-21

Risk Information

CVSS v2

Base Score: 9.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Severity: High