CVE-2018-8379 is a remote code execution vulnerability in Microsoft Excel, including Excel 2013 RT, stemming from improper handling of objects in memory. This high-severity flaw (CVSS 7.8) requires user interaction (UI:R) for exploitation, typically via a malicious file, but can lead to complete compromise of confidentiality, integrity, and availability (C:H/I:H/A:H). While the vulnerability has a high FAUCET Risk Score of 95/100 and a notable EPSS score, there is no evidence of active exploitation, publicly available exploit code in Metasploit or ExploitDB, or inclusion in CISA's KEV catalog. Community discussion and media coverage are minimal, with only one article mentioning it as part of Microsoft's August 2018 Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:excel:2010:sp2:*:*:*:*:*:* | ||
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:excel:2013:sp1:*:*:*:*:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:excel:2016:*:*:*:*:*:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:excel:2016:*:*:*:click-to-run:*:*:* | ||
sp1CPE matchmatch criteria | cpe:2.3:a:microsoft:excel_2013_rt:sp1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.