vulnerability

Microsoft CVE-2018-8310: Microsoft Office Tampering Vulnerability

Severity
5
CVSS
(AV:N/AC:L/Au:N/C:N/I:P/A:N)
Published
Jul 10, 2018
Added
Jul 10, 2018
Modified
Sep 12, 2018

Description

A tampering vulnerability exists when Microsoft Outlook does not properly handle specific attachment types when rendering HTML emails. An attacker could exploit the vulnerability by sending a specially crafted email and attachment to a victim, or by hosting a malicious .eml file on a web server.
The attacker who successfully exploited the vulnerability could then embed untrusted TrueType fonts in the body of an email. This behavior could be combined with other exploits to further compromise a user's system.
The security update addresses the vulnerability by correcting how Microsoft Outlook handles attachments.

Solutions

msft-kb4022200-12082010-6335-4b4e-9067-bb9ab71cf1b0msft-kb4022200-5e56bb37-37bc-455c-bf4c-cb13d8f9df01msft-kb4022202-4750b50e-d34a-4137-a403-4a184745a23dmsft-kb4022202-59253783-a245-4897-993e-57a2ed30c0e0msft-kb4022224-319c401f-2099-495f-acd9-0bb12e0173d0msft-kb4022224-58ac224c-7014-40c6-aaf7-dce9179e6305
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.