An information disclosure vulnerability exists when Office renders Rich Text Format (RTF) email messages containing OLE objects when a message is opened or previewed, aka "Microsoft Office Information Disclosure Vulnerability." This affects Microsoft Word, Microsoft Office. This CVE ID is unique from CVE-2018-1007.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Microsoft Office | — | Download and install Microsoft KB4018339 | Jun 20, 2023 | Apr 12, 2018 |
| Msft | — | Security Update for Microsoft Word 2010 (KB4018359) 32-Bit EditionSecurity Update for Microsoft Word 2010 (KB4018359) 64-Bit EditionSecurity Update for Microsoft Office Compatibility Pack Service Pack 3 (KB4018354)Security Update for Microsoft Word 2013 (KB4018347) 32-Bit EditionSecurity Update for Microsoft Word 2013 (KB4018347) 64-Bit EditionSecurity Update for Microsoft Office Word 2007 (KB4018355)Security Update for Microsoft Office 2010 (KB4018357) 64-Bit EditionSecurity Update for Microsoft Office 2010 (KB4018357) 32-Bit Edition | Apr 10, 2018 | Apr 10, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub