First published: Wed Jul 11 2018(Updated: )
A tampering vulnerability exists when Microsoft Outlook does not properly handle specific attachment types when rendering HTML emails, aka "Microsoft Office Tampering Vulnerability." This affects Microsoft Word, Microsoft Office.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office | =2010-sp2 | |
Microsoft Office | =2016 | |
Microsoft Word | =2010-sp2 | |
Microsoft Word | =2013-sp1 | |
Microsoft Word | =2013-sp1 | |
Microsoft Word | =2016 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-8310 is a tampering vulnerability in Microsoft Outlook and Microsoft Word that allows attackers to manipulate attachments in HTML emails.
CVE-2018-8310 affects Microsoft Office by exploiting a vulnerability in the way Microsoft Outlook and Microsoft Word handle specific attachment types when rendering HTML emails.
CVE-2018-8310 has a severity rating of 7.5, indicating a high severity.
CVE-2018-8310 affects Microsoft Office 2010 SP2, Microsoft Office 2016, Microsoft Word 2010 SP2, Microsoft Word 2013 SP1, and Microsoft Word 2016.
To fix CVE-2018-8310, it is recommended to apply the latest security patches provided by Microsoft.