Microsoft Excel Information Disclosure Vulnerability
Released: Dec 11, 2018
- Assigning CNA
- Microsoft
- CVE.org link
- CVE-2018-8627
Executive Summary
An information disclosure vulnerability exists when Microsoft Excel software reads out of bound memory due to an uninitialized variable, which could disclose the contents of memory. An attacker who successfully exploited the vulnerability could view out of bound memory.
Exploitation of the vulnerability requires that a user open a specially crafted file with an affected version of Microsoft Excel software.
The security update addresses the vulnerability by properly initializing the affected variable.
Exploitability
The following table provides an exploitability assessment for this vulnerability at the time of original publication.
- Publicly disclosed
- No
- Exploited
- No
- Exploitability assessment
- Exploitation Less Likely
FAQ
What type of information could be disclosed by this vulnerability?
The type of information that could be disclosed if an attacker successfully exploited this vulnerability is uninitialized memory.
Acknowledgements
- Yangkang(@dnpushme) & Jinquan(@jq0904) of Qihoo360 CoreSecurity(@360CoreSec)
Security Updates
To determine the support lifecycle for your software, see the Microsoft Support Lifecycle.
- -
- Security Update
- -
- Security Update
- -
- -
- Security Update
- -
- Security Update
- -
- -
- -
- -
- -
- -
- -
- Security Update
- -
- -
- -
- -
- -
- -
- -
Disclaimer
Revisions
Information published.