CVE Database
/

CVE-2018-1028

Back to search

CVE-2018-1028

Published: Apr 12, 2018

Modified: Aug 5, 2024

PUBLISHED

Description

A remote code execution vulnerability exists when the Office graphics component improperly handles specially crafted embedded fonts, aka "Microsoft Office Graphics Remote Code Execution Vulnerability." This affects Word, Microsoft Office, Microsoft SharePoint, Excel, Microsoft SharePoint Server.

VendorProductVersions

Microsoft

Word

affected
Automation Services on Microsoft SharePoint Server 2010 Service Pack 2
affected
Automation Services on Microsoft SharePoint Server 2013 Service Pack 1

Microsoft

Microsoft Office

affected
2010 Service Pack 2 (32-bit editions)
affected
2010 Service Pack 2 (64-bit editions)
affected
2013 RT Service Pack 1
affected
2013 Service Pack 1 (32-bit editions)
affected
2013 Service Pack 1 (64-bit editions)

+4 more versions

Microsoft

Microsoft SharePoint

affected
Enterprise Server 2016

Microsoft

Excel

affected
Services on Microsoft SharePoint Enterprise Server 2013 Service Pack 1

Microsoft

Microsoft SharePoint Server

affected
2013 Service Pack 1

References

1040654
vdb-entry
x_refsource_SECTRACK
103641
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now