Unrated severityNVD Advisory· Published Mar 14, 2018· Updated Sep 17, 2024
CVE-2018-0919
CVE-2018-0919
Description
Microsoft Office 2010 SP2, 2013 SP1, and 2016, Microsoft Office 2016 Click-to-Run Microsoft Office 2016 for Mac, Microsoft Office Web Apps 2010 SP2, Microsoft Office Web Apps 2013 SP1, Microsoft SharePoint Enterprise Server 2013 SP1, Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2010 SP2, Microsoft Word 2010 SP2, Word 2013 SP1 and Microsoft Word 2016 allow an information disclosure vulnerability due to how variables are initialized, aka "Microsoft Office Information Disclosure Vulnerability".
Affected products
4- Range: 2016
- Range: 2016
- Microsoft Corporation/Microsoft Officev5Range: Microsoft Office 2010 SP2, 2013 SP1, and 2016, Microsoft Office 2016 Click-to-Run Microsoft Office 2016 for Mac, Microsoft Office Web Apps 2010 SP2, Microsoft Office Web Apps 2013 SP1, Microsoft SharePoint Enterprise Server 2013 SP1, Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2010 SP2, Microsoft Word 2010 SP2, Word 2013 SP1 and Microsoft Word 2016
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.securityfocus.com/bid/103311mitrevdb-entryx_refsource_BID
- www.securitytracker.com/id/1040526mitrevdb-entryx_refsource_SECTRACK
- portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0919mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.