CVE-2018-0797 is a remote code execution vulnerability affecting Microsoft Office 2010, 2013, and 2016, as well as related products like SharePoint and Word Viewer, stemming from improper handling of RTF content. With a CVSS score of 7.8 (High), it can be exploited with low attack complexity through user interaction, potentially leading to high impact on confidentiality, integrity, and availability. While it was mentioned in media coverage as a zero-day at the time of its disclosure, there is no public exploit code available in common databases like Metasploit or ExploitDB, and it is not currently listed on CISA's KEV catalog. Community discussion and media coverage indicate significant attention at the time of its discovery.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2010:sp2:*:*:*:*:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2016:*:*:*:*:mac_os_x:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:office_compatibility_pack:-:sp3:*:*:*:*:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:office_online_server:2016:*:*:*:*:*:*:* | ||
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:office_web_apps:2010:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.