First published: Wed Oct 10 2018(Updated: )
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in Protected View, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Excel.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office Excel | =2010-sp2 | |
Microsoft Office Excel | =2013-sp1 | |
Microsoft Office Excel | =2013-sp1 | |
Microsoft Office Excel | =2016 | |
Microsoft Office | =2010-sp2 | |
Microsoft Office | =2013-sp1 | |
Microsoft Office | =2013-sp1 | |
Microsoft Office | =2016 | |
Microsoft Office | =2019 | |
Microsoft Office 365 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-8502 is rated as critical as it can allow remote code execution.
To fix CVE-2018-8502, ensure that you install the latest security updates provided by Microsoft for affected versions.
CVE-2018-8502 affects Microsoft Excel from versions 2010 through 2019, including Office 365 ProPlus.
CVE-2018-8502 is a remote code execution vulnerability caused by improper handling of objects in Protected View.
Yes, CVE-2018-8502 can be exploited by opening a malicious Excel file received via email.