CVE-2018-8427 (CNNVD-201810-298)

MEDIUM
中文标题:
Microsoft Graphics Components 信息泄露漏洞
英文标题:
An information disclosure vulnerability exists in the way that Microsoft Graphics Components handle ...
CVSS分数: 5.5
发布时间: 2018-10-10 13:00:00
漏洞类型: 信息泄露
状态: PUBLISHED
数据质量分数: 0.30
数据版本: v3
漏洞描述
中文描述:

Microsoft Windows Server 2008 SP2等都是美国微软(Microsoft)公司的产品。Microsoft Windows Server 2008 SP2是一套服务器使用的操作系统。PowerPoint Viewer 2007是一款演示文稿处理程序。Graphics Components是其中的一个图形组件。 Microsoft Graphics Components中对内存对象的处理方式存在信息泄露漏洞。攻击者可借助特制的文件利用该漏洞获取信息。以下产品和版本受到影响:Microsoft Windows Server 2008 SP2;PowerPoint Viewer 2007;Office Word Viewer;Office Compatibility Pack SP3,Office 365 ProPlus,Office 2019,Office 2016 for Mac;Excel Viewer 2007 SP3。

英文描述:

An information disclosure vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka "Microsoft Graphics Components Information Disclosure Vulnerability." This affects Microsoft Office, Microsoft Office Word Viewer, Office 365 ProPlus, Windows Server 2008, Microsoft PowerPoint Viewer, Microsoft Excel Viewer.

CWE类型:
CWE-200
标签:
(暂无数据)
受影响产品
厂商 产品 版本 版本范围 平台 CPE
Microsoft Microsoft Office 2016 for Mac - - cpe:2.3:a:microsoft:microsoft_office:2016_for_mac:*:*:*:*:*:*:*
Microsoft Microsoft Office 2019 for 32-bit editions - - cpe:2.3:a:microsoft:microsoft_office:2019_for_32-bit_editions:*:*:*:*:*:*:*
Microsoft Microsoft Office 2019 for 64-bit editions - - cpe:2.3:a:microsoft:microsoft_office:2019_for_64-bit_editions:*:*:*:*:*:*:*
Microsoft Microsoft Office Compatibility Pack Service Pack 3 - - cpe:2.3:a:microsoft:microsoft_office:compatibility_pack_service_pack_3:*:*:*:*:*:*:*
Microsoft Microsoft Office Word Viewer Microsoft Office Word Viewer - - cpe:2.3:a:microsoft:microsoft_office_word_viewer:microsoft_office_word_viewer:*:*:*:*:*:*:*
Microsoft Windows Server 2008 32-bit Systems Service Pack 2 - - cpe:2.3:a:microsoft:windows_server_2008:32-bit_systems_service_pack_2:*:*:*:*:*:*:*
Microsoft Windows Server 2008 32-bit Systems Service Pack 2 (Server Core installation) - - cpe:2.3:a:microsoft:windows_server_2008:32-bit_systems_service_pack_2_(server_core_installation):*:*:*:*:*:*:*
Microsoft Windows Server 2008 Itanium-Based Systems Service Pack 2 - - cpe:2.3:a:microsoft:windows_server_2008:itanium-based_systems_service_pack_2:*:*:*:*:*:*:*
Microsoft Windows Server 2008 x64-based Systems Service Pack 2 - - cpe:2.3:a:microsoft:windows_server_2008:x64-based_systems_service_pack_2:*:*:*:*:*:*:*
Microsoft Windows Server 2008 x64-based Systems Service Pack 2 (Server Core installation) - - cpe:2.3:a:microsoft:windows_server_2008:x64-based_systems_service_pack_2_(server_core_installation):*:*:*:*:*:*:*
Microsoft Microsoft PowerPoint Viewer 2007 - - cpe:2.3:a:microsoft:microsoft_powerpoint_viewer:2007:*:*:*:*:*:*:*
Microsoft Office 365 ProPlus for 32-bit Systems - - cpe:2.3:a:microsoft:office:365_proplus_for_32-bit_systems:*:*:*:*:*:*:*
Microsoft Office 365 ProPlus for 64-bit Systems - - cpe:2.3:a:microsoft:office:365_proplus_for_64-bit_systems:*:*:*:*:*:*:*
Microsoft Microsoft Excel Viewer 2007 Service Pack 3 - - cpe:2.3:a:microsoft:microsoft_excel_viewer:2007_service_pack_3:*:*:*:*:*:*:*
microsoft excel_viewer 2007 - - cpe:2.3:a:microsoft:excel_viewer:2007:sp3:*:*:*:*:*:*
microsoft office 2016 - - cpe:2.3:a:microsoft:office:2016:*:*:*:*:mac_os_x:*:*
microsoft office 2019 - - cpe:2.3:a:microsoft:office:2019:*:*:*:*:*:*:*
microsoft office_365_proplus - - - cpe:2.3:a:microsoft:office_365_proplus:-:*:*:*:*:*:*:*
microsoft office_compatibility_pack - - - cpe:2.3:a:microsoft:office_compatibility_pack:-:sp3:*:*:*:*:*:*
microsoft office_word_viewer - - - cpe:2.3:a:microsoft:office_word_viewer:-:*:*:*:*:*:*:*
microsoft powerpoint_viewer 2007 - - cpe:2.3:a:microsoft:powerpoint_viewer:2007:*:*:*:*:*:*:*
microsoft windows_server_2008 - - - cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*
解决方案
中文解决方案:
(暂无数据)
英文解决方案:
(暂无数据)
临时解决方案:
(暂无数据)
参考链接
1041823 vdb-entry
cve.org
访问
105453 vdb-entry
cve.org
访问
无标题 x_refsource_CONFIRM
cve.org
访问
CVSS评分详情
5.5
MEDIUM
CVSS向量: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS版本: 3.0
机密性
HIGH
完整性
NONE
可用性
NONE
时间信息
发布时间:
2018-10-10 13:00:00
修改时间:
2024-08-05 06:54:36
创建时间:
2025-11-11 15:35:22
更新时间:
2025-11-11 15:54:04
利用信息
暂无可利用代码信息
数据源详情
数据源 记录ID 版本 提取时间
CVE cve_CVE-2018-8427 2025-11-11 15:19:55 2025-11-11 07:35:22
NVD nvd_CVE-2018-8427 2025-11-11 14:55:59 2025-11-11 07:43:56
CNNVD cnnvd_CNNVD-201810-298 2025-11-11 15:10:06 2025-11-11 07:54:04
版本与语言
当前版本: v3
主要语言: EN
支持语言:
EN ZH
安全公告
暂无安全公告信息
变更历史
v3 CNNVD
2025-11-11 15:54:04
vulnerability_type: 未提取 → 信息泄露; cnnvd_id: 未提取 → CNNVD-201810-298; data_sources: ['cve', 'nvd'] → ['cnnvd', 'cve', 'nvd']
查看详细变更
  • vulnerability_type: 未提取 -> 信息泄露
  • cnnvd_id: 未提取 -> CNNVD-201810-298
  • data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
v2 NVD
2025-11-11 15:43:56
cvss_score: 未提取 → 5.5; cvss_vector: NOT_EXTRACTED → CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N; cvss_version: NOT_EXTRACTED → 3.0; affected_products_count: 14 → 22; data_sources: ['cve'] → ['cve', 'nvd']
查看详细变更
  • cvss_score: 未提取 -> 5.5
  • cvss_vector: NOT_EXTRACTED -> CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
  • cvss_version: NOT_EXTRACTED -> 3.0
  • affected_products_count: 14 -> 22
  • data_sources: ['cve'] -> ['cve', 'nvd']