CVE-2018-8432 is a remote code execution vulnerability within Microsoft Graphics Components, impacting various Windows versions (7, 10, Server 2008, 2019) and Microsoft Office products (Office, Office 365 ProPlus, Excel Viewer, PowerPoint Viewer, Word Viewer). This vulnerability carries a high CVSS score of 7.8, indicating a significant risk where an attacker could achieve high confidentiality, integrity, and availability impacts with low attack complexity, though user interaction is required. While the EPSS score suggests a moderate likelihood of exploitation, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in CISA's KEV catalog. Community discussion and media coverage are minimal, with only one article noting its inclusion in a past patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2007CPE matchmatch criteria | cpe:2.3:a:microsoft:excel_viewer:2007:sp3:*:*:*:*:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2016:*:mac_os:*:*:*:*:* | ||
2019CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2019:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:office_365_proplus:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:office_compatibility_pack:-:sp3:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.