CVE-2018-0802
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE is unique from CVE-2018-0797 and CVE-2018-0812.
- Affected products
- Office, Wordpad, Office Word
- Microsoft Office
- = 2007, 2010, 2013, 2016
- Microsoft Office Compatibility Pack
- All versions
- Microsoft Word
- = 2007, 2010, 2013, 2016
- CVSS 2.0
- 9.3 HIGH
- CVSS 3.1
- 7.8 HIGH
- EPSS
- 93.3% (100th percentile)
- Weakness
- CWE-787
- NVD status
- Analyzed
- Published
- 2018-01-10
CVE-2018-0802 at NVD
12 known exploits for CVE-2018-0802
Proof-of-concept code and exploit modules indexed by Sploitus
RTF_11882_0802
CVE-2018-0802_POC
CVE-2018-0802
CVE-2018-0802
CVE-2018-0802_CVE-2017-11882
Maldoc-Analysis
Exploit for Out-of-bounds Write in Microsoft
Exploit for Improper Restriction of Operations within the Bounds of a Memory Buffer in Microsoft
Exploit for Improper Restriction of Operations within the Bounds of a Memory Buffer in Microsoft
Exploit for Improper Restriction of Operations within the Bounds of a Memory Buffer in Microsoft
Exploit for Out-of-bounds Write in Microsoft
Exploit for Out-of-bounds Write in Microsoft