CVE-2018-8378: Medium severity microsoft office excel viewer vulnerability
An information disclosure vulnerability exists when Microsoft Office software reads out of bound memory due to an uninitialized variable, which could disclose the contents of memory, aka "Microsoft Office Information Disclosure Vulnerability." This affects Word, Microsoft SharePoint Server, Microsoft Office Word Viewer, Microsoft Excel Viewer, Microsoft SharePoint, Microsoft Office.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-8378?
CVE-2018-8378 is an information disclosure vulnerability in Microsoft Office software that allows an attacker to read out-of-bound memory and disclose its contents.
Which software is affected by CVE-2018-8378?
The software affected by CVE-2018-8378 includes Microsoft Excel Viewer 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Office Compatibility Pack SP3, Microsoft Office Web Apps 2010 SP2, Microsoft Office Web Apps 2013 SP1, Microsoft Office Word Viewer, Microsoft SharePoint Enterprise Server 2013 SP1, Microsoft SharePoint Enterprise Server 2016, and Microsoft SharePoint Server 2013 SP1.
How severe is CVE-2018-8378?
CVE-2018-8378 has a severity rating of 5.5 (medium).
What is the Common Weakness Enumeration (CWE) code for CVE-2018-8378?
The CWE codes for CVE-2018-8378 are CWE-125 (Out-of-bounds Read) and CWE-908 (Use of Uninitialized Variable).
Where can I find more information about CVE-2018-8378?
You can find more information about CVE-2018-8378 on the SecurityFocus website and the Microsoft Security Guidance Advisory.