CVE-2018-8627 (CNNVD-201812-452)
中文标题:
Microsoft Excel 信息泄露漏洞
英文标题:
An information disclosure vulnerability exists when Microsoft Excel software reads out of bound memo...
漏洞描述
中文描述:
Microsoft Excel是美国微软(Microsoft)公司Office套件中的一款电子表格处理软件。 Microsoft Excel中存在信息泄露漏洞。攻击者可借助特制的文件利用该漏洞查看越界内存。以下产品和版本受到影响:Excel Services(Microsoft SharePoint Server 2010 SP2);Microsoft Excel 2010 SP2;Microsoft Excel 2013 RT SP1,Microsoft Excel 2013 SP1,Microsoft Excel 2016,Microsoft Excel Viewer 2007 SP3;Microsoft Office 2010 SP2,Microsoft Office 2016,Microsoft Office 2019,Microsoft Office Compatibility Pack SP3;Office 365 ProPlus。
英文描述:
An information disclosure vulnerability exists when Microsoft Excel software reads out of bound memory due to an uninitialized variable, which could disclose the contents of memory, aka "Microsoft Excel Information Disclosure Vulnerability." This affects Microsoft Office, Office 365 ProPlus, Microsoft Excel, Microsoft Excel Viewer, Excel. This CVE ID is unique from CVE-2018-8598.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| Microsoft | Microsoft Office | 2010 Service Pack 2 (32-bit editions) | - | - |
cpe:2.3:a:microsoft:microsoft_office:2010_service_pack_2_(32-bit_editions):*:*:*:*:*:*:*
|
| Microsoft | Microsoft Office | 2010 Service Pack 2 (64-bit editions) | - | - |
cpe:2.3:a:microsoft:microsoft_office:2010_service_pack_2_(64-bit_editions):*:*:*:*:*:*:*
|
| Microsoft | Microsoft Office | 2016 for Mac | - | - |
cpe:2.3:a:microsoft:microsoft_office:2016_for_mac:*:*:*:*:*:*:*
|
| Microsoft | Microsoft Office | 2019 for 32-bit editions | - | - |
cpe:2.3:a:microsoft:microsoft_office:2019_for_32-bit_editions:*:*:*:*:*:*:*
|
| Microsoft | Microsoft Office | 2019 for 64-bit editions | - | - |
cpe:2.3:a:microsoft:microsoft_office:2019_for_64-bit_editions:*:*:*:*:*:*:*
|
| Microsoft | Microsoft Office | 2019 for Mac | - | - |
cpe:2.3:a:microsoft:microsoft_office:2019_for_mac:*:*:*:*:*:*:*
|
| Microsoft | Microsoft Office | Compatibility Pack Service Pack 3 | - | - |
cpe:2.3:a:microsoft:microsoft_office:compatibility_pack_service_pack_3:*:*:*:*:*:*:*
|
| Microsoft | Microsoft Excel | 2010 Service Pack 2 (32-bit editions) | - | - |
cpe:2.3:a:microsoft:microsoft_excel:2010_service_pack_2_(32-bit_editions):*:*:*:*:*:*:*
|
| Microsoft | Microsoft Excel | 2010 Service Pack 2 (64-bit editions) | - | - |
cpe:2.3:a:microsoft:microsoft_excel:2010_service_pack_2_(64-bit_editions):*:*:*:*:*:*:*
|
| Microsoft | Microsoft Excel | 2013 RT Service Pack 1 | - | - |
cpe:2.3:a:microsoft:microsoft_excel:2013_rt_service_pack_1:*:*:*:*:*:*:*
|
| Microsoft | Microsoft Excel | 2013 Service Pack 1 (32-bit editions) | - | - |
cpe:2.3:a:microsoft:microsoft_excel:2013_service_pack_1_(32-bit_editions):*:*:*:*:*:*:*
|
| Microsoft | Microsoft Excel | 2013 Service Pack 1 (64-bit editions) | - | - |
cpe:2.3:a:microsoft:microsoft_excel:2013_service_pack_1_(64-bit_editions):*:*:*:*:*:*:*
|
| Microsoft | Microsoft Excel | 2016 (32-bit edition) | - | - |
cpe:2.3:a:microsoft:microsoft_excel:2016_(32-bit_edition):*:*:*:*:*:*:*
|
| Microsoft | Microsoft Excel | 2016 (64-bit edition) | - | - |
cpe:2.3:a:microsoft:microsoft_excel:2016_(64-bit_edition):*:*:*:*:*:*:*
|
| Microsoft | Microsoft Excel Viewer | 2007 Service Pack 3 | - | - |
cpe:2.3:a:microsoft:microsoft_excel_viewer:2007_service_pack_3:*:*:*:*:*:*:*
|
| Microsoft | Excel | Services on Microsoft SharePoint Server 2010 Service Pack 2 | - | - |
cpe:2.3:a:microsoft:excel:services_on_microsoft_sharepoint_server_2010_service_pack_2:*:*:*:*:*:*:*
|
| Microsoft | Office | 365 ProPlus for 32-bit Systems | - | - |
cpe:2.3:a:microsoft:office:365_proplus_for_32-bit_systems:*:*:*:*:*:*:*
|
| Microsoft | Office | 365 ProPlus for 64-bit Systems | - | - |
cpe:2.3:a:microsoft:office:365_proplus_for_64-bit_systems:*:*:*:*:*:*:*
|
| microsoft | excel | 2010 | - | - |
cpe:2.3:a:microsoft:excel:2010:sp2:*:*:*:*:*:*
|
| microsoft | excel | 2013 | - | - |
cpe:2.3:a:microsoft:excel:2013:sp1:*:*:*:*:*:*
|
| microsoft | excel | 2016 | - | - |
cpe:2.3:a:microsoft:excel:2016:*:*:*:*:*:*:*
|
| microsoft | excel_viewer | 2007 | - | - |
cpe:2.3:a:microsoft:excel_viewer:2007:sp3:*:*:*:*:*:*
|
| microsoft | office | 2010 | - | - |
cpe:2.3:a:microsoft:office:2010:sp2:*:*:*:*:*:*
|
| microsoft | office | 2016 | - | - |
cpe:2.3:a:microsoft:office:2016:*:*:*:*:mac_os_x:*:*
|
| microsoft | office | 2019 | - | - |
cpe:2.3:a:microsoft:office:2019:*:*:*:*:*:*:*
|
| microsoft | office_365_proplus | - | - | - |
cpe:2.3:a:microsoft:office_365_proplus:-:*:*:*:*:*:*:*
|
| microsoft | office_compatibility_pack | - | - | - |
cpe:2.3:a:microsoft:office_compatibility_pack:-:sp3:*:*:*:*:*:*
|
| microsoft | sharepoint_server | 2010 | - | - |
cpe:2.3:a:microsoft:sharepoint_server:2010:sp2:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2018-8627 |
2025-11-11 15:19:55 | 2025-11-11 07:35:22 |
| NVD | nvd_CVE-2018-8627 |
2025-11-11 14:56:01 | 2025-11-11 07:43:56 |
| CNNVD | cnnvd_CNNVD-201812-452 |
2025-11-11 15:10:08 | 2025-11-11 07:54:15 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 信息泄露
- cnnvd_id: 未提取 -> CNNVD-201812-452
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- cvss_score: 未提取 -> 5.5
- cvss_vector: NOT_EXTRACTED -> CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
- cvss_version: NOT_EXTRACTED -> 3.0
- affected_products_count: 18 -> 28
- data_sources: ['cve'] -> ['cve', 'nvd']