Show plain JSON{"id": "CVE-2018-8378", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 4.3, "accessVector": "NETWORK", "vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N", "authentication": "NONE", "integrityImpact": "NONE", "accessComplexity": "MEDIUM", "availabilityImpact": "NONE", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 2.9, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 8.6, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": true}], "cvssMetricV30": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.0", "baseScore": 5.5, "attackVector": "LOCAL", "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N", "integrityImpact": "NONE", "userInteraction": "REQUIRED", "attackComplexity": "LOW", "availabilityImpact": "NONE", "privilegesRequired": "NONE", "confidentialityImpact": "HIGH"}, "impactScore": 3.6, "exploitabilityScore": 1.8}]}, "published": "2018-08-15T17:29:07.267", "references": [{"url": "http://www.securityfocus.com/bid/104996", "tags": ["Third Party Advisory", "VDB Entry"], "source": "secure@microsoft.com"}, {"url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8378", "tags": ["Patch", "Vendor Advisory"], "source": "secure@microsoft.com"}], "vulnStatus": "Analyzed", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-125"}, {"lang": "en", "value": "CWE-908"}]}], "descriptions": [{"lang": "en", "value": "An information disclosure vulnerability exists when Microsoft Office software reads out of bound memory due to an uninitialized variable, which could disclose the contents of memory, aka \"Microsoft Office Information Disclosure Vulnerability.\" This affects Word, Microsoft SharePoint Server, Microsoft Office Word Viewer, Microsoft Excel Viewer, Microsoft SharePoint, Microsoft Office."}, {"lang": "es", "value": "Existe una vulnerabilidad de divulgaci\u00f3n de informaci\u00f3n cuando el software de Microsoft Office lee memoria fuera de l\u00edmites debido a una variable no inicializada, lo que podr\u00eda divulgar los contenidos de memoria. Esto tambi\u00e9n se conoce como \"Microsoft Office Information Disclosure Vulnerability\". Esto afecta a Word, Microsoft SharePoint Server, Microsoft Office Word Viewer, Microsoft Excel Viewer, Microsoft SharePoint y Microsoft Office."}], "lastModified": "2020-08-24T17:37:01.140", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:microsoft:excel_viewer:2007:sp3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E4635DA5-27DA-43FF-92AC-A9F80218A2F0"}, {"criteria": "cpe:2.3:a:microsoft:office:2010:sp2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "081DE1E3-4622-4C32-8B9C-9AEC1CD20638"}, {"criteria": "cpe:2.3:a:microsoft:office:2013:sp1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "120690A6-E0A1-4E36-A35A-C87109ECC064"}, {"criteria": "cpe:2.3:a:microsoft:office:2013:sp1:*:*:rt:*:*:*", "vulnerable": true, "matchCriteriaId": "F7DDFFB8-2337-4DD7-8120-56CC8EF134B4"}, {"criteria": "cpe:2.3:a:microsoft:office:2016:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E0B3B0BC-C7C6-4687-AD72-DCA29FF9AE3A"}, {"criteria": "cpe:2.3:a:microsoft:office:2016:*:*:*:click-to-run:*:*:*", "vulnerable": true, "matchCriteriaId": "E74CB3D6-B0D7-4A6C-ABAA-170C7710D856"}, {"criteria": "cpe:2.3:a:microsoft:office_compatibility_pack:-:sp3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "71AF058A-2E5D-4B11-88DB-8903C64B13C1"}, {"criteria": "cpe:2.3:a:microsoft:office_web_apps:2010:sp2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A8235774-4B57-4793-BE26-2CDE67532EDD"}, {"criteria": "cpe:2.3:a:microsoft:office_web_apps:2013:sp1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B3C3FC9A-D8E5-493A-A575-C831A9A28815"}, {"criteria": "cpe:2.3:a:microsoft:office_word_viewer:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C64B2636-8F96-48BA-921F-A8FA0E62DE63"}, {"criteria": "cpe:2.3:a:microsoft:sharepoint_enterprise_server_2013:-:sp1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8725A383-4813-4220-8D2E-4CB86D0EC119"}, {"criteria": "cpe:2.3:a:microsoft:sharepoint_enterprise_server_2016:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "67F75889-16AE-44C3-85C9-818A856A0D5D"}, {"criteria": "cpe:2.3:a:microsoft:sharepoint_server:2013:sp1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "16F33176-442C-4EFF-8EA0-C640D203B939"}], "operator": "OR"}]}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:microsoft:word_automation_services:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CC865581-3650-4DC4-9138-C2F71AA3B850"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:microsoft:sharepoint_server:2010:sp2:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "9A57C675-05A9-4BC2-AE95-7CA5CA6B1F73"}], "operator": "OR"}], "operator": "AND"}], "sourceIdentifier": "secure@microsoft.com"}