First published: Tue Jan 09 2018(Updated: )
Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Office Remote Code Execution Vulnerability".
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office | =2010-sp2 | |
Microsoft Office | =2016 | |
Microsoft Office | =2016 | |
Microsoft Office Word | =2013-sp1 | |
Microsoft Office Word | =2013-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-0795 is classified as a critical remote code execution vulnerability in Microsoft Office products.
To mitigate CVE-2018-0795, ensure that you apply the latest security updates provided by Microsoft for affected Office versions.
CVE-2018-0795 affects Microsoft Office 2010, 2013, and 2016, including specific service packs.
CVE-2018-0795 can be exploited via specially crafted Office documents that allow remote code execution.
While Microsoft recommends installing updates, disabling macros in Office applications can serve as a temporary workaround for CVE-2018-0795.