106120vdb entry
http://www.securityfocus.com/bid/106120 CVE-2018-8627
MEDIUM
Microsoft Excel Use of Uninitialized Resource
Record summary
CVE-2018-8627 has a selected CVSS score of 5.5 (medium).
Description
An information disclosure vulnerability exists when Microsoft Excel software reads out of bound memory due to an uninitialized variable, which could disclose the contents of memory, aka "Microsoft Excel Information Disclosure Vulnerability." This affects Microsoft Office, Office 365 ProPlus, Microsoft Excel, Microsoft Excel Viewer, Excel. This CVE ID is unique from CVE-2018-8598.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jan 21, 2021 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Affected products and versions
5| Product | Source | Version range | Status |
|---|---|---|---|
| VulnCheck, CVE List | Services on Microsoft SharePoint Server 2010 Service Pack 2 | affected | |
Microsoft ExcelBrowse Microsoft / Microsoft Excel | CVE List | 2010 Service Pack 2 (32-bit editions) | affected |
| 2010 Service Pack 2 (64-bit editions) | affected | ||
| 2013 RT Service Pack 1 | affected | ||
| 2013 Service Pack 1 (32-bit editions) | affected | ||
| 2013 Service Pack 1 (64-bit editions) | affected | ||
| 2016 (32-bit edition) | affected | ||
| 2016 (64-bit edition) | affected | ||
Microsoft Excel ViewerBrowse Microsoft / Microsoft Excel Viewer | CVE List | 2007 Service Pack 3 | affected |
Microsoft OfficeBrowse Microsoft / Microsoft Office | CVE List | 2010 Service Pack 2 (32-bit editions) | affected |
| 2010 Service Pack 2 (64-bit editions) | affected | ||
| 2016 for Mac | affected | ||
| 2019 for 32-bit editions | affected | ||
| 2019 for 64-bit editions | affected | ||
| 2019 for Mac | affected | ||
| Compatibility Pack Service Pack 3 | affected | ||
| CVE List | 365 ProPlus for 32-bit Systems | affected | |
| 365 ProPlus for 64-bit Systems | affected |
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-8627 portal.msrc.microsoft.comConfirmation
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8627