imPC@ndo IT

Tracker / CVE-2018-1028

CVE-2018-1028

High 8.8

A remote code execution vulnerability exists when the Office graphics component improperly handles specially crafted embedded fonts, aka "Microsoft Office Graphics Remote Code Execution Vulnerability." This affects Word, Microsoft Office, Microsoft SharePoint, Excel, Microsoft SharePoint Server.

Affected products and versions

microsoft excel_services
microsoft office
microsoft office_2010
microsoft office_web_apps
microsoft sharepoint_enterprise_server
microsoft word_automation_services

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References