CVE Vulnerabilities

CVE-2018-8627

Use of Uninitialized Resource

Published: Dec 12, 2018 | Modified: Nov 21, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

An information disclosure vulnerability exists when Microsoft Excel software reads out of bound memory due to an uninitialized variable, which could disclose the contents of memory, aka Microsoft Excel Information Disclosure Vulnerability. This affects Microsoft Office, Office 365 ProPlus, Microsoft Excel, Microsoft Excel Viewer, Excel. This CVE ID is unique from CVE-2018-8598.

Weakness

The product uses or accesses a resource that has not been initialized.

Affected Software

NameVendorStart VersionEnd Version
ExcelMicrosoft2010-sp2 (including)2010-sp2 (including)
ExcelMicrosoft2013-sp1 (including)2013-sp1 (including)
ExcelMicrosoft2016 (including)2016 (including)
Excel_viewerMicrosoft2007-sp3 (including)2007-sp3 (including)
OfficeMicrosoft2010-sp2 (including)2010-sp2 (including)
OfficeMicrosoft2016 (including)2016 (including)
OfficeMicrosoft2019 (including)2019 (including)
Office_365_proplusMicrosoft- (including)- (including)
Office_compatibility_packMicrosoft–sp3 (including)–sp3 (including)
Sharepoint_serverMicrosoft2010-sp2 (including)2010-sp2 (including)

Potential Mitigations

References