First published: Wed Dec 12 2018(Updated: )
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Excel. This CVE ID is unique from CVE-2018-8597.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Excel for Mac | =2010-sp2 | |
Microsoft Excel for Mac | =2013-sp1 | |
Microsoft Excel for Mac | =2013-sp1 | |
Microsoft Excel for Mac | =2016 | |
Microsoft Excel for Mac | =2019 | |
Microsoft Office 365 ProPlus |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-8636 is rated as critical due to its potential for remote code execution.
To mitigate CVE-2018-8636, users should apply the latest security updates provided by Microsoft for affected Excel versions.
CVE-2018-8636 affects Microsoft Excel 2010 SP2, 2013 SP1, 2016, 2019, and Office 365 ProPlus.
CVE-2018-8636 can be exploited to allow an attacker to execute arbitrary code on the victim's system.
The primary recommendation for CVE-2018-8636 is to update to the latest version of Excel, as no effective workaround exists.