Junglewise Threat Intelligence

CVE-2018-0802: Microsoft Office Memory Corruption Vulnerability

CVE-2018-0802 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2021-11-03

Technologies: Microsoft Office, Microsoft Word 2016, Microsoft Office 2016. Vendors: Microsoft.

Executive brief

Equation Editor in Microsoft Office contains a memory corruption vulnerability due to improper object handling in memory. A remote attacker can exploit this by convincing a user to open a specially crafted file, resulting in remote code execution in the context of the current user.

Affected products

  • Microsoft Office 2007 Service Pack 3
  • Microsoft Office 2010 Service Pack 2
  • Microsoft Office 2013 Service Pack 1
  • Microsoft Office 2016
  • Microsoft Word 2007 Service Pack 3
  • Microsoft Word 2010 Service Pack 2
  • Microsoft Word 2013 Service Pack 1
  • Microsoft Word 2016
  • Microsoft Office Compatibility Pack Service Pack 3

Timeline

  • 2018-01-09: disclosed: Initial Microsoft advisory publication date based on CVE ID and external references.
  • 2021-11-03: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog.
  • 2021-11-03: exploited: Confirmed as exploited in the wild.

Related threats