← All CVEs

CVE-2018-8628

high · 7.8

A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle objects in memory, aka "Microsoft PowerPoint Remote Code Execution Vulnerability." This affects Microsoft Office, Office 365 ProPlus, Microsoft PowerPoint, Microsoft SharePoint, Microsoft PowerPoint Viewer, Office Online Server, Microsoft SharePoint Server.

7.8
CVSS
15.9%
EPSS (exploit prob.)
97th
EPSS percentile
2018-12-12
Published

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

VendorProductAffected versions
microsoftoffice2016
microsoftoffice2019
microsoftoffice2019
microsoftoffice_365_proplusall versions
microsoftoffice_compatibility_packall versions
microsoftoffice_online_serverall versions
microsoftoffice_web_apps2010
microsoftoffice_web_apps2013
microsoftpowerpoint2010
microsoftpowerpoint2013
microsoftpowerpoint2016
microsoftpowerpoint_viewerall versions
microsoftsharepoint_enterprise_server2016
microsoftsharepoint_server2013
microsoftsharepoint_server2019

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2018-8628