CVE-2018-8587 is a remote code execution vulnerability in Microsoft Outlook, affecting Office 365 ProPlus and Microsoft Office, stemming from improper memory object handling. It carries a CVSS score of 7.8 (High), indicating a significant risk with high impact on confidentiality, integrity, and availability, requiring user interaction for exploitation. Although not listed in CISA's KEV catalog, this vulnerability was reportedly exploited as a zero-day, with media coverage confirming its active use at the time of discovery. Despite its past exploitation, there are no public Metasploit, Nuclei, or ExploitDB modules available, though community discussion and media coverage suggest notable attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2010:sp2:*:*:*:*:*:* | ||
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2013:sp1:*:*:*:*:*:* | ||
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2013:sp1:*:*:rt:*:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2016:*:*:*:*:*:*:* | ||
2019CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2019:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.