CVE-2018-8310
A tampering vulnerability exists when Microsoft Outlook does not properly handle specific attachment types when rendering HTML emails, aka "Microsoft Office Tampering Vulnerability." This affects Microsoft Word, Microsoft Office.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.36%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A tampering vulnerability exists when Microsoft Outlook does not properly handle specific attachment types when rendering HTML emails, aka "Microsoft Office Tampering Vulnerability." This affects Microsoft Word, Microsoft Office.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 5.36% probability · 92th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/office · microsoft/word
- Source
- secure@microsoft.com
References
- http://www.securityfocus.com/bid/104615Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041274Third Party Advisory, VDB Entry
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8310Patch, Vendor Advisory
- http://www.securityfocus.com/bid/104615Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041274Third Party Advisory, VDB Entry
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8310Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.