CVE Vulnerabilities

CVE-2018-0850

Published: Feb 15, 2018 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Microsoft Outlook 2007, Microsoft Outlook 2010, Microsoft Outlook 2013, Microsoft Outlook 2016, and Microsoft Office 2016 Click-to-Run allow an elevation of privilege vulnerability due to how the format of incoming message is validated, aka Microsoft Outlook Elevation of Privilege Vulnerability.

Affected Software

NameVendorStart VersionEnd Version
OfficeMicrosoft2016 (including)2016 (including)
OutlookMicrosoft2007 (including)2007 (including)
OutlookMicrosoft2010 (including)2010 (including)
OutlookMicrosoft2013 (including)2013 (including)
OutlookMicrosoft2016 (including)2016 (including)

References