CVE-2018-0819 is a spoofing vulnerability in Microsoft Office 2016 for Mac, specifically affecting how Outlook for Mac displays encoded email addresses. This flaw enables attackers to craft malicious email attachments that facilitate social engineering attacks like phishing. With a CVSS score of 6.5 (Medium), the vulnerability requires user interaction (UI:R) and can lead to high integrity impact (I:H) if exploited, though it does not affect confidentiality or availability. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Despite this, the vulnerability has garnered significant community discussion and media coverage, indicating awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2016:*:*:*:*:mac_os_x:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.