CVE-2018-8427
moderate-risk
Published 2018-10-10
An information disclosure vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka "Microsoft Graphics Components Information Disclosure Vulnerability." This affects Microsoft Office, Microsoft Office Word Viewer, Office 365 ProPlus, Windows Server 2008, Microsoft PowerPoint Viewer, Microsoft Excel Viewer.
Do I need to act?
~
6.3% chance of exploitation in next 30 days
EPSS score — moderate exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
5
CVSS 5.5/10
Medium
LOCAL
/ LOW complexity
Affected Products (8)
Affected Vendors
References (6)
Third Party Advisory
http://www.securityfocus.com/bid/105453
Third Party Advisory
http://www.securitytracker.com/id/1041823
Third Party Advisory
http://www.securityfocus.com/bid/105453
Third Party Advisory
http://www.securitytracker.com/id/1041823
41
/ 100
moderate-risk
Severity
18/34 · Moderate
Exploitability
9/34 · Low
Exposure
14/34 · Moderate