CVE-2018-8161 (CNNVD-201805-259)
中文标题:
Microsoft Office 缓冲区错误漏洞
英文标题:
A remote code execution vulnerability exists in Microsoft Office software when the software fails to...
漏洞描述
中文描述:
Microsoft Office 2010 SP2等都是美国微软(Microsoft)公司的产品。Microsoft Office 2010 SP2是一款办公软件套件产品。Word 2007 SP3是一款文字处理软件。 Microsoft Office中存在远程代码执行漏洞,该漏洞源于程序没有正确的处理内存中的对象。远程攻击者可通过使用受影响的Microsoft Office版本打开特制的文件利用该漏洞在当前用户的上下文中运行任意代码。以下产品和版本受到影响:Microsoft Office 2010 SP2,Microsoft Office Web Apps 2010 SP2,Microsoft Office Web Apps Server 2013 SP1,Microsoft SharePoint Enterprise Server 2016,Microsoft Word 2010 SP2,Microsoft Word 2013 RT SP1,Microsoft Word 2013 SP1,Microsoft Word 2016,Word Automation Services。
英文描述:
A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka "Microsoft Office Remote Code Execution Vulnerability." This affects Microsoft Word, Word, Microsoft Office, Microsoft SharePoint. This CVE ID is unique from CVE-2018-8157, CVE-2018-8158.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| Microsoft | Microsoft Word | 2010 Service Pack 2 (32-bit editions) | - | - |
cpe:2.3:a:microsoft:microsoft_word:2010_service_pack_2_(32-bit_editions):*:*:*:*:*:*:*
|
| Microsoft | Microsoft Word | 2010 Service Pack 2 (64-bit editions) | - | - |
cpe:2.3:a:microsoft:microsoft_word:2010_service_pack_2_(64-bit_editions):*:*:*:*:*:*:*
|
| Microsoft | Microsoft Word | 2013 RT Service Pack 1 | - | - |
cpe:2.3:a:microsoft:microsoft_word:2013_rt_service_pack_1:*:*:*:*:*:*:*
|
| Microsoft | Microsoft Word | 2013 Service Pack 1 (32-bit editions) | - | - |
cpe:2.3:a:microsoft:microsoft_word:2013_service_pack_1_(32-bit_editions):*:*:*:*:*:*:*
|
| Microsoft | Microsoft Word | 2013 Service Pack 1 (64-bit editions) | - | - |
cpe:2.3:a:microsoft:microsoft_word:2013_service_pack_1_(64-bit_editions):*:*:*:*:*:*:*
|
| Microsoft | Microsoft Word | 2016 (32-bit edition) | - | - |
cpe:2.3:a:microsoft:microsoft_word:2016_(32-bit_edition):*:*:*:*:*:*:*
|
| Microsoft | Microsoft Word | 2016 (64-bit edition) | - | - |
cpe:2.3:a:microsoft:microsoft_word:2016_(64-bit_edition):*:*:*:*:*:*:*
|
| Microsoft | Word | Automation Services on Microsoft SharePoint Server 2010 Service Pack 2 | - | - |
cpe:2.3:a:microsoft:word:automation_services_on_microsoft_sharepoint_server_2010_service_pack_2:*:*:*:*:*:*:*
|
| Microsoft | Word | Automation Services on Microsoft SharePoint Server 2013 Service Pack 1 | - | - |
cpe:2.3:a:microsoft:word:automation_services_on_microsoft_sharepoint_server_2013_service_pack_1:*:*:*:*:*:*:*
|
| Microsoft | Microsoft Office | 2010 Service Pack 2 (32-bit editions) | - | - |
cpe:2.3:a:microsoft:microsoft_office:2010_service_pack_2_(32-bit_editions):*:*:*:*:*:*:*
|
| Microsoft | Microsoft Office | 2010 Service Pack 2 (64-bit editions) | - | - |
cpe:2.3:a:microsoft:microsoft_office:2010_service_pack_2_(64-bit_editions):*:*:*:*:*:*:*
|
| Microsoft | Microsoft Office | Web Apps 2010 Service Pack 2 | - | - |
cpe:2.3:a:microsoft:microsoft_office:web_apps_2010_service_pack_2:*:*:*:*:*:*:*
|
| Microsoft | Microsoft Office | Web Apps Server 2013 Service Pack 1 | - | - |
cpe:2.3:a:microsoft:microsoft_office:web_apps_server_2013_service_pack_1:*:*:*:*:*:*:*
|
| Microsoft | Microsoft SharePoint | Enterprise Server 2016 | - | - |
cpe:2.3:a:microsoft:microsoft_sharepoint:enterprise_server_2016:*:*:*:*:*:*:*
|
| microsoft | office | 2010 | - | - |
cpe:2.3:a:microsoft:office:2010:sp2:*:*:*:*:*:*
|
| microsoft | office | 2013 | - | - |
cpe:2.3:a:microsoft:office:2013:sp1:*:*:*:*:*:*
|
| microsoft | office | 2016 | - | - |
cpe:2.3:a:microsoft:office:2016:*:*:*:*:*:*:*
|
| microsoft | office_web_apps | 2010 | - | - |
cpe:2.3:a:microsoft:office_web_apps:2010:sp2:*:*:*:*:*:*
|
| microsoft | office_web_apps | 2013 | - | - |
cpe:2.3:a:microsoft:office_web_apps:2013:sp1:*:*:*:*:*:*
|
| microsoft | sharepoint_server | 2010 | - | - |
cpe:2.3:a:microsoft:sharepoint_server:2010:sp2:*:*:*:*:*:*
|
| microsoft | sharepoint_server | 2013 | - | - |
cpe:2.3:a:microsoft:sharepoint_server:2013:sp1:*:*:*:*:*:*
|
| microsoft | sharepoint_server | 2016 | - | - |
cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:*:*:*:*
|
| microsoft | word | 2010 | - | - |
cpe:2.3:a:microsoft:word:2010:sp2:*:*:*:*:*:*
|
| microsoft | word | 2013 | - | - |
cpe:2.3:a:microsoft:word:2013:sp1:*:*:*:*:*:*
|
| microsoft | word | 2016 | - | - |
cpe:2.3:a:microsoft:word:2016:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2018-8161 |
2025-11-11 15:19:54 | 2025-11-11 07:35:22 |
| NVD | nvd_CVE-2018-8161 |
2025-11-11 14:55:54 | 2025-11-11 07:43:56 |
| CNNVD | cnnvd_CNNVD-201805-259 |
2025-11-11 15:10:01 | 2025-11-11 07:53:44 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 缓冲区错误
- cnnvd_id: 未提取 -> CNNVD-201805-259
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- severity: SeverityLevel.MEDIUM -> SeverityLevel.HIGH
- cvss_score: 未提取 -> 7.8
- cvss_vector: NOT_EXTRACTED -> CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- cvss_version: NOT_EXTRACTED -> 3.0
- affected_products_count: 14 -> 25
- data_sources: ['cve'] -> ['cve', 'nvd']