CVE-2018-8382 is an information disclosure vulnerability in Microsoft Excel, Excel Viewer, and Office products, where the software improperly reveals memory contents. It carries a CVSS score of 5.5 (MEDIUM), indicating a local attack vector requiring user interaction, with the primary impact being confidentiality compromise. While the FAUCET Risk Score is high at 81/100 and it has a notable EPSS score, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in CISA's KEV catalog. Community discussion and media coverage are minimal, with only one article mentioning it in the context of August 2018 Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:excel:2010:sp2:*:*:*:*:*:* | ||
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:excel:2013:sp1:*:*:*:*:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:excel:2016:*:*:*:*:*:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:excel:2016:*:*:*:click-to-run:*:*:* | ||
sp1CPE matchmatch criteria | cpe:2.3:a:microsoft:excel_2013_rt:sp1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.