← All CVEs

CVE-2018-1028

high · 8.8

A remote code execution vulnerability exists when the Office graphics component improperly handles specially crafted embedded fonts, aka "Microsoft Office Graphics Remote Code Execution Vulnerability." This affects Word, Microsoft Office, Microsoft SharePoint, Excel, Microsoft SharePoint Server.

8.8
CVSS
19.3%
EPSS (exploit prob.)
97th
EPSS percentile
2018-04-12
Published

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Weaknesses

CWE-94

Affected products

VendorProductAffected versions
microsoftexcel_servicesall versions
microsoftoffice2013
microsoftoffice2013_rt
microsoftoffice2016
microsoftoffice_2010all versions
microsoftoffice_web_apps2010
microsoftoffice_web_apps2013
microsoftsharepoint_enterprise_server2013
microsoftsharepoint_enterprise_server2016
microsoftword_automation_servicesall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2018-1028