Microsoft Office Information Disclosure Vulnerability
🔗 CVE IDs covered (1)
📋 Description
An information disclosure vulnerability exists when Office renders Rich Text Format (RTF) email messages containing OLE objects when a message is opened or previewed. This vulnerability could potentially result in the disclosure of sensitive information to a malicious site. To exploit the vulnerability, an attacker would have to send an RTF-formatted email to a user and convince the user to open or preview the email. A connection to a remote SMB server could then be automatically initiated, enabling the attacker to brute-force attack the corresponding NTLM challenge and response in order to disclose the corresponding hash password. The security update addresses the vulnerability by correcting how Office processes OLE objects.
🎯 Affected products13
- Microsoft Office 2010 Service Pack 2 (32-bit editions)
- Microsoft Office 2010 Service Pack 2 (64-bit editions)
- Microsoft Office 2016 Click-to-Run (C2R) for 32-bit editions
- Microsoft Office 2016 Click-to-Run (C2R) for 64-bit editions
- Microsoft Office Compatibility Pack Service Pack 3
- Microsoft Word 2007 Service Pack 3
- Microsoft Word 2010 Service Pack 2 (32-bit editions)
- Microsoft Word 2010 Service Pack 2 (64-bit editions)
- Microsoft Word 2013 RT Service Pack 1
- Microsoft Word 2013 Service Pack 1 (32-bit editions)
- Microsoft Word 2013 Service Pack 1 (64-bit editions)
- Microsoft Word 2016 (32-bit edition)
- Microsoft Word 2016 (64-bit edition)
✅ Remediation
KB4018355 (Security Update) KB4018359 (Security Update) KB4018347 (Security Update) KB4018339 (Security Update) KBClick to Run (Security Update) KB4018357 (Security Update) KB4018354 (Security Update)
🔗 References (6)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2018-0950
- patchhttps://www.microsoft.com/downloads/details.aspx?familyid=def0d181-207b-4448-bc2c-6037043cbaed
- patchhttps://www.microsoft.com/downloads/details.aspx?familyid=03f4f40a-2fda-4592-a2b4-d67796e30dcd
- patchhttps://www.microsoft.com/downloads/details.aspx?familyid=bb18a0d7-d0e4-4d55-946b-a54e998567e7
- patchhttps://www.microsoft.com/downloads/details.aspx?familyid=08789693-0ff3-49c0-be08-169bbffa1d59
- patchhttps://www.microsoft.com/downloads/details.aspx?familyid=c6fd1491-d0f0-4667-be62-a37b3f7069c7