CVE-2018-1028
high · 8.8A remote code execution vulnerability exists when the Office graphics component improperly handles specially crafted embedded fonts, aka "Microsoft Office Graphics Remote Code Execution Vulnerability." This affects Word, Microsoft Office, Microsoft SharePoint, Excel, Microsoft SharePoint Server.
8.8
CVSS
19.3%
EPSS (exploit prob.)
97th
EPSS percentile
2018-04-12
Published
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weaknesses
CWE-94
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | excel_services | all versions |
| microsoft | office | 2013 |
| microsoft | office | 2013_rt |
| microsoft | office | 2016 |
| microsoft | office_2010 | all versions |
| microsoft | office_web_apps | 2010 |
| microsoft | office_web_apps | 2013 |
| microsoft | sharepoint_enterprise_server | 2013 |
| microsoft | sharepoint_enterprise_server | 2016 |
| microsoft | word_automation_services | all versions |
Check a specific version with /api/v1/cve/match.
References
- http://www.securityfocus.com/bid/103641
- http://www.securitytracker.com/id/1040654
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-1028
- http://www.securityfocus.com/bid/103641
- http://www.securitytracker.com/id/1040654
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-1028
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2018-1028