CVE-2018-0806: Critical severity microsoft office vulnerability
Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Remote Code Execution Vulnerability". This CVE is unique from CVE-2018-0804, CVE-2018-0805, and CVE-2018-0807.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-0806?
CVE-2018-0806 is a remote code execution vulnerability in Equation Editor in various versions of Microsoft Office.
Which versions of Microsoft Office are affected by CVE-2018-0806?
Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 are affected.
What is the severity of CVE-2018-0806?
CVE-2018-0806 has a severity rating of 8.8, which is considered critical.
How does CVE-2018-0806 allow remote code execution?
CVE-2018-0806 allows remote code execution due to the way objects are handled in memory.
Are there any available fixes for CVE-2018-0806?
Yes, Microsoft has released a security advisory with guidance on mitigating the vulnerability.