CVE-2018-0794: Critical severity Microsoft Office vulnerability
Microsoft Word in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Remote Code Execution Vulnerability". This CVE is unique from CVE-2018-0792.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-0794?
CVE-2018-0794 is a remote code execution vulnerability in Microsoft Word in various versions of Microsoft Office.
Which versions of Microsoft Office are affected by CVE-2018-0794?
Microsoft Word in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 are affected.
What is the severity of CVE-2018-0794?
The severity of CVE-2018-0794 is critical with a CVSS score of 8.8.
How does CVE-2018-0794 allow remote code execution?
CVE-2018-0794 allows remote code execution due to the way objects are handled in memory in Microsoft Word.
How can I mitigate the vulnerability CVE-2018-0794?
Microsoft has provided security guidance and patches for CVE-2018-0794. Update your Microsoft Office installations to the latest version or apply the provided patches.