A security feature bypass vulnerability in Microsoft Excel would allow a local user to perform arbitrary code execution.
Microsoft Office Access Connectivity Engine contains an unspecified vulnerability which can allow for remote code execution.
Microsoft is investigating reports of a series of remote code execution vulnerabilities impacting Windows and Office products. Microsoft is aware of targeted attacks that attempt to exploit these vulnerabilities by using specially-crafted Microsoft Office documents.
An attacker could create a specially crafted Microsoft Office document that enables them to perform remote code execution in the context of the victim. However, an attacker would have to convince the victim to open the malicious file.
Upon completion of this investigation, Microsoft will take the appropriate action to help protect our customers. This might include providing a security update through our monthly release process or providing an out-of-cycle security update, depending on customer needs.
Please see the Microsoft Threat Intelligence Blog https://aka.ms/Storm-0978 Entry for important information about steps you can take to protect your system from this vulnerability.
This CVE will be updated with new information and links to security updates when they become available.
Microsoft Excel Remote Code Execution Vulnerability
Microsoft Office contains a security feature bypass vulnerability in which reliance on untrusted inputs in a security decision in Microsoft Office could allow an unauthorized attacker to bypass a security feature locally. Some of the impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.
Microsoft Access Remote Code Execution Vulnerability
Microsoft Word contains an unspecified vulnerability that allows for information disclosure.
Microsoft Outlook contains a security feature bypass vulnerability that allows an attacker to bypass the Microsoft Outlook Security Notice prompt.
Microsoft Office Elevation of Privilege Vulnerability
Microsoft Office Outlook contains a privilege escalation vulnerability that allows for a NTLM Relay attack against another service to authenticate as the user.
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'.
A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML Engine Remote Code Execution Vulnerability." This affects Microsoft Office, Microsoft Office Word Viewer, Internet Explorer 9, Internet Explorer 11, Microsoft Excel Viewer, Internet Explorer 10, Office 365 ProPlus.
Microsoft Access Remote Code Execution Vulnerability
Microsoft Access Remote Code Execution Vulnerability
Microsoft Access Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
Improper input validation in Microsoft Office Outlook allows an authorized attacker to execute code locally.
Microsoft PowerPoint Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
Microsoft Office Spoofing Vulnerability