15/2/2018
17/9/2024
CVE-2018-0850
First published: Thu Feb 15 2018(Updated: )
Microsoft Outlook 2007, Microsoft Outlook 2010, Microsoft Outlook 2013, Microsoft Outlook 2016, and Microsoft Office 2016 Click-to-Run allow an elevation of privilege vulnerability due to how the format of incoming message is validated, aka "Microsoft Outlook Elevation of Privilege Vulnerability".
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|
Microsoft Office | =2016 | |
Microsoft Outlook | =2007 | |
Microsoft Outlook | =2010 | |
Microsoft Outlook | =2013 | |
Microsoft Outlook | =2016 | |
Never miss a vulnerability like this again
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
Frequently Asked Questions
What is CVE-2018-0850?
CVE-2018-0850 is an elevation of privilege vulnerability in Microsoft Outlook and Microsoft Office.
Which versions of Microsoft Outlook and Microsoft Office are affected by CVE-2018-0850?
Microsoft Outlook 2007, 2010, 2013, 2016 and Microsoft Office 2016 Click-to-Run are affected.
What is the severity of CVE-2018-0850?
The severity of CVE-2018-0850 is medium with a CVSS score of 6.5.
How does CVE-2018-0850 affect Microsoft Outlook and Microsoft Office?
CVE-2018-0850 allows an elevation of privilege due to how the format of incoming messages is validated.
How can I fix CVE-2018-0850?
Apply the latest security updates and patches provided by Microsoft to mitigate CVE-2018-0850.
- collector/nvd-index
- agent/references
- agent/severity
- agent/author
- agent/type
- agent/description
- agent/remedy
- agent/last-modified-date
- agent/tags
- agent/event
- agent/first-publish-date
- agent/softwarecombine
- collector/mitre-cve
- source/MITRE
- vendor/microsoft
- canonical/microsoft office
- version/microsoft office/2016
- canonical/microsoft outlook
- version/microsoft outlook/2007
- version/microsoft outlook/2010
- version/microsoft outlook/2013
- version/microsoft outlook/2016
Contact
SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.coBy using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203