[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247862

 
 

909

 
 

194603

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Microsoft Office Information Disclosure Vulnerability - CVE-2018-0950

ID: oval:org.secpod.oval:def:44950Date: (C)2018-04-11   (M)2023-07-13
Class: VULNERABILITYFamily: windows




An information disclosure vulnerability exists when Office renders Rich Text Format (RTF) email messages containing OLE objects when a message is opened or previewed. This vulnerability could potentially result in the disclosure of sensitive information to a malicious site. To exploit the vulnerability, an attacker would have to send an RTF-formatted email to a user and convince the user to open or preview the email. A connection to a remote SMB server could then be automatically initiated, enabling the attacker to brute-force attack the corresponding NTLM challenge and response in order to disclose the corresponding hash password. The security update addresses the vulnerability by correcting how Office processes OLE objects.

Platform:
Microsoft Windows Server 2022
Microsoft Windows 11
Microsoft Windows Server 2019
Microsoft Windows 7
Microsoft Windows 8
Microsoft Windows 8.1
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2012
Microsoft Windows Server 2012 R2
Microsoft Windows Vista
Microsoft Windows 10
Microsoft Windows Server 2008 R2
Microsoft Windows Server 2016
Microsoft Windows XP
Product:
Microsoft 365 Apps for Enterprise
Microsoft Office Compatibility Pack
Microsoft Word 2007
Microsoft Word 2010
Microsoft Word 2013
Microsoft Word 2016
Reference:
CVE-2018-0950
CVE    1
CVE-2018-0950
CPE    11
cpe:/a:microsoft:word:2016
cpe:/a:microsoft:word:2007
cpe:/a:microsoft:office_compatibility_pack:-:sp3
cpe:/a:microsoft:word:2007:sp3
...

© SecPod Technologies