Vulnerability Name:

CVE-2018-8427 (CCN-150394)

Assigned:2018-10-09
Published:2018-10-09
Updated:2018-11-27
Summary:An information disclosure vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka "Microsoft Graphics Components Information Disclosure Vulnerability." This affects Microsoft Office, Microsoft Office Word Viewer, Office 365 ProPlus, Windows Server 2008, Microsoft PowerPoint Viewer, Microsoft Excel Viewer.
CVSS v3 Severity:5.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
4.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): None
Availibility (A): None
4.7 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N)
4.1 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): High
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
3.8 Low (CCN CVSS v2 Vector: AV:L/AC:H/Au:S/C:C/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): High
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Complete
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-200
Vulnerability Consequences:Obtain Information
References:Source: MITRE
Type: CNA
CVE-2018-8427

Source: BID
Type: Third Party Advisory, VDB Entry
105453

Source: CCN
Type: BID-105453
Microsoft Windows Graphics Component CVE-2018-8427 Information Disclosure Vulnerability

Source: SECTRACK
Type: Third Party Advisory, VDB Entry
1041823

Source: XF
Type: UNKNOWN
ms-graphics-cve20188427-info-disc(150394)

Source: CCN
Type: Microsoft Security TechCenter - October 2018
Microsoft Windows Graphics Components Information Disclosure Vulnerability

Source: CONFIRM
Type: Patch, Vendor Advisory
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8427

Vulnerable Configuration:Configuration 1:
  • cpe:/a:microsoft:excel_viewer:2007:sp3:*:*:*:*:*:*
  • OR cpe:/a:microsoft:office:2016:*:*:*:*:mac_os_x:*:*
  • OR cpe:/a:microsoft:office:2019:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:office_365_proplus:-:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:office_compatibility_pack:-:sp3:*:*:*:*:*:*
  • OR cpe:/a:microsoft:office_word_viewer:-:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:powerpoint_viewer:2007:*:*:*:*:*:*:*
  • OR cpe:/o:microsoft:windows_server_2008:*:sp2:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:microsoft:excel_viewer:*:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:word_viewer:*:*:*:*:*:*:*:*
  • OR cpe:/o:microsoft:windows_server_2008:*:sp2:*:*:*:*:x32:*
  • OR cpe:/o:microsoft:windows_server_2008:*:sp2:*:*:*:*:x64:*
  • OR cpe:/a:microsoft:powerpoint_viewer:2007:*:*:*:*:*:*:*
  • OR cpe:/o:microsoft:windows_server_2008:*:sp2:*:*:*:*:itanium:*
  • OR cpe:/a:microsoft:office_compatibility_pack:*:sp3:*:*:*:*:*:*
  • OR cpe:/a:microsoft:office:2016:*:*:*:*:mac:*:*
  • OR cpe:/a:microsoft:office:2019:*:~~~click-to-run~~:*:*:*:x32:*
  • OR cpe:/a:microsoft:office:2019:*:*:*:click-to-run:*:x64:*
  • OR cpe:/a:microsoft:office_365_proplus:-:*:*:*:*:*:x32:*
  • OR cpe:/a:microsoft:office_365_proplus:-:*:*:*:*:*:x64:*
  • AND
  • cpe:/o:microsoft:windows:*:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    microsoft excel viewer 2007 sp3
    microsoft office 2016
    microsoft office 2019
    microsoft office 365 proplus -
    microsoft office compatibility pack - sp3
    microsoft office word viewer -
    microsoft powerpoint viewer 2007
    microsoft windows server 2008 - sp2
    microsoft excel viewer *
    microsoft word viewer *
    microsoft windows server 2008 sp2
    microsoft windows server 2008 sp2
    microsoft powerpoint viewer 2007
    microsoft windows server 2008
    microsoft office compatibility pack * sp3
    microsoft office 2016
    microsoft office 2019
    microsoft office 2019
    microsoft office 365 proplus -
    microsoft office 365 proplus -
    microsoft windows *