CVE-2018-0903
Microsoft Access 2010 SP2, Microsoft Access 2013 SP1, Microsoft Access 2016, and Microsoft Office 2016 Click-to-Run allow a remote code execution vulnerability due to how objects are handled in memory, aka "Microsoft Access Remote Code Execution…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 16.0%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Microsoft Access 2010 SP2, Microsoft Access 2013 SP1, Microsoft Access 2016, and Microsoft Office 2016 Click-to-Run allow a remote code execution vulnerability due to how objects are handled in memory, aka "Microsoft Access Remote Code Execution Vulnerability".
- CVSS 3.0
- 7.8 HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 15.97% probability · 97th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/access · microsoft/office
- Source
- secure@microsoft.com
References
- http://www.securityfocus.com/bid/103315Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040503Third Party Advisory, VDB Entry
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0903Patch, Vendor Advisory
- http://www.securityfocus.com/bid/103315Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040503Third Party Advisory, VDB Entry
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0903Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.