First published: Wed Oct 10 2018(Updated: )
A remote code execution vulnerability exists in Microsoft Word software when the software fails to properly handle objects in Protected View, aka "Microsoft Word Remote Code Execution Vulnerability." This affects Microsoft SharePoint Server, Office 365 ProPlus, Microsoft Office, Microsoft Word.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office | =2010-sp2 | |
Microsoft Office | =2013-sp1 | |
Microsoft Office | =2013-sp1 | |
Microsoft Office | =2016 | |
Microsoft Office | =2019 | |
Microsoft Office 365 Proplus | ||
Microsoft Office Web Apps | =2010-sp2 | |
Microsoft SharePoint Server | =2010-sp2 | |
Microsoft Word | =2010-sp2 | |
Microsoft Word | =2013-sp1 | |
Microsoft Word | =2013-sp1 | |
Microsoft Word | =2016 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-8504 is a remote code execution vulnerability in Microsoft Word software when it fails to properly handle objects in Protected View.
The severity of CVE-2018-8504 is critical with a CVSS score of 8.8.
Microsoft SharePoint Server, Office 365 ProPlus, Microsoft Office, and Microsoft Word are affected by CVE-2018-8504.
Apply the latest security updates and patches provided by Microsoft for the affected software.
You can find more information about CVE-2018-8504 on the following websites: [SecurityFocus](http://www.securityfocus.com/bid/105499), [SecurityTracker](http://www.securitytracker.com/id/1041840), and the [Microsoft Security Guidance Advisory](https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8504).