Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerability · NVD

CVE-2018-0919

CVE-2018-0919, low severity (CVSS 3.3): 3 tracked apps concerned, all fixed or indeterminable on their current version.

Severity (CVSS)
3.3

NVD scale

Exploitation
11.7 %

EPSS, predicted over 30 days

Tracked apps
3
Still exposed
0

Microsoft Office 2010 SP2, 2013 SP1, and 2016, Microsoft Office 2016 Click-to-Run Microsoft Office 2016 for Mac, Microsoft Office Web Apps 2010 SP2, Microsoft Office Web Apps 2013 SP1, Microsoft SharePoint Enterprise Server 2013 SP1, Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2010 SP2, Microsoft Word 2010 SP2, Word 2013 SP1 and Microsoft Word 2016 allow an information disclosure vulnerability due to how variables are initialized, aka "Microsoft Office Information Disclosure Vulnerability".

Attack vector : Local No privileges required
Show raw CVSS vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
EPSS 11.66% moderate exploit risk percentile 95.7%

Tracked apps referencing this CVE

For each app: the affected range, the fixing version, and where the tracked app stands today.

NVD references 7 distinct products for this CVE : only those tracked by Scout (mobile and desktop catalog apps) are listed above. Libraries, servers and out-of-scope products do not appear here. Full list on NVD ↗

Vulnerable CPE configurations (13)
Vendor Product Versions
microsoft office
All platforms (wildcard)
-
microsoft office
All platforms (wildcard)
-
microsoft office
macOS
-
microsoft office
All platforms (wildcard)
-
microsoft office
All platforms (wildcard)
-
microsoft word
All platforms (wildcard)
-
microsoft word
All platforms (wildcard)
-
microsoft word
All platforms (wildcard)
-
microsoft word
All platforms (wildcard)
-
microsoft word
All platforms (wildcard)
-
microsoft word
All platforms (wildcard)
-
microsoft word
All platforms (wildcard)
-
microsoft word
All platforms (wildcard)
-
View on NVD ↗ Advisory · portal.msrc.microsoft.com