CVE-2018-8247
Summary
| CVE | CVE-2018-8247 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-06-14 12:29:00 UTC |
| Updated | 2019-10-03 00:03:00 UTC |
| Description | An elevation of privilege vulnerability exists when Office Web Apps Server 2013 and Office Online Server fail to properly handle web requests, aka "Microsoft Office Elevation of Privilege Vulnerability." This affects Microsoft Office, Microsoft Office Online Server. This CVE ID is unique from CVE-2018-8245. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Office Online Server | 2016 | All | All | All |
| Application | Microsoft | Office Online Server | 2016 | All | All | All |
| Application | Microsoft | Office Web Apps | 2013 | sp1 | All | All |
| Application | Microsoft | Office Web Apps | 2013 | sp1 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8247 | CONFIRM | portal.msrc.microsoft.com | Patch, Vendor Advisory |
| Microsoft Office CVE-2018-8247 Privilege Escalation Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Microsoft Office Web Apps Server Script Injection Flaw Lets Remote Users Obtain Potentially Sensitive Information on the Target System - SecurityTracker | SECTRACK | www.securitytracker.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.