Microsoft Corporation Vulnerabilities and Affected Products
Vulnerabilities associated with Equation Editor.
Products
Clear product- Microsoft Edge90 vulnerabilities
- Microsoft Windows63 vulnerabilities
- Internet Explorer46 vulnerabilities
- Microsoft Office45 vulnerabilities
- Windows kernel41 vulnerabilities
- ChakraCore, Microsoft Edge40 vulnerabilities
- Windows33 vulnerabilities
- Windows Uniscribe30 vulnerabilities
- Browser20 vulnerabilities
- Microsoft Scripting Engine18 vulnerabilities
- Microsoft SharePoint17 vulnerabilities
- Windows Hyper-V17 vulnerabilities
- Office14 vulnerabilities
- Edge13 vulnerabilities
- Equation Editor12 vulnerabilities
- Hyper-V12 vulnerabilities
- ChakraCore, Microsoft Edge, Internet Explorer10 vulnerabilities
- ASP.NET Core9 vulnerabilities
- Microsoft Edge, ChakraCore9 vulnerabilities
- ChakraCore8 vulnerabilities
- Uniscribe8 vulnerabilities
- Win32k8 vulnerabilities
- Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 20168 vulnerabilities
- Internet Explorer, Microsoft Edge7 vulnerabilities
- Malware Protection Engine7 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2018-0848HIGH | Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Remote Code Execution Vulnerability". This CVE is unique from CVE-2018-0805, CVE-2018-0806, and CVE-2018-0807. Jan 22, 2018 | CVSS8.8v3.0 | EPSS20.5% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-0845HIGH | Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Remote Code Execution Vulnerability". This CVE is unique from CVE-2018-0805, CVE-2018-0806, and CVE-2018-0807. Jan 22, 2018 | CVSS7.8v3.0 | EPSS19.7% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-0862HIGH | Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Remote Code Execution Vulnerability". This CVE is unique from CVE-2018-0805, CVE-2018-0806, and CVE-2018-0807. Jan 22, 2018 | CVSS8.8v3.0 | EPSS18.6% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-0849HIGH | Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Remote Code Execution Vulnerability". This CVE is unique from CVE-2018-0805, CVE-2018-0806, and CVE-2018-0807. Jan 22, 2018 | CVSS8.8v3.0 | EPSS18.6% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-0812HIGH | Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Memory Corruption Vulnerability". CWE-787Jan 10, 2018 | CVSS7.8v3.0 | EPSS23.9% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-0804HIGH | Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Remote Code Execution Vulnerability". This CVE is unique from CVE-2018-0805, CVE-2018-0806, and CVE-2018-0807. Jan 10, 2018 | CVSS8.8v3.0 | EPSS24.4% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-0806HIGH | Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Remote Code Execution Vulnerability". This CVE is unique from CVE-2018-0804, CVE-2018-0805, and CVE-2018-0807. Jan 10, 2018 | CVSS8.8v3.0 | EPSS24.6% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-0802HIGH | Microsoft Office Memory Corruption VulnerabilityEquation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE is unique from CVE-2018-0797 and CVE-2018-0812. CWE-787Jan 10, 2018 | CVSS7.8v3.1 | EPSS87.4% | PoCs4 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-0805HIGH | Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Remote Code Execution Vulnerability". This CVE is unique from CVE-2018-0804, CVE-2018-0806, and CVE-2018-0807 Jan 10, 2018 | CVSS8.8v3.0 | EPSS24.4% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-0807HIGH | Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Remote Code Execution Vulnerability". This CVE is unique from CVE-2018-0804, CVE-2018-0805, and CVE-2018-0806. Jan 10, 2018 | CVSS8.8v3.0 | EPSS24.4% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-0801HIGH | Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Office Remote Code Execution Vulnerability". Jan 10, 2018 | CVSS8.8v3.0 | EPSS24.4% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-0798HIGH | Microsoft Office Memory Corruption VulnerabilityEquation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Office Memory Corruption Vulnerability". CWE-787Jan 10, 2018 | CVSS8.8v3.1 | EPSS91% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |