CVE-2018-8378 is an information disclosure vulnerability in Microsoft Office products, including Word, Excel Viewer, and SharePoint, stemming from an uninitialized variable leading to out-of-bounds memory reads. This medium-severity vulnerability (CVSS 5.5) requires user interaction (e.g., opening a malicious file) and local access to exploit, potentially disclosing memory contents but not impacting integrity or availability. While the EPSS score indicates low exploitability, there is no public exploit code (Metasploit, Nuclei, ExploitDB) and it is not listed in CISA's KEV catalog, suggesting no active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2007CPE matchmatch criteria | cpe:2.3:a:microsoft:excel_viewer:2007:sp3:*:*:*:*:*:* | ||
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2010:sp2:*:*:*:*:*:* | ||
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2013:sp1:*:*:*:*:*:* | ||
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2013:sp1:*:*:rt:*:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2016:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.