CVE-2018-8245 is a remote code execution vulnerability in Microsoft Publisher, stemming from its failure to properly secure OLE object instantiation within the Local Machine zone. This flaw carries a high CVSS score of 7.8, indicating that an attacker could achieve full compromise of confidentiality, integrity, and availability with low attack complexity, though user interaction is required. Despite its high severity and potential for significant impact, there is no evidence of active exploitation, nor are public exploit modules or proof-of-concept codes readily available. Community discussion and media coverage are minimal, suggesting limited public awareness or interest in this particular vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:publisher:2010:sp2:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.