CVE-2018-8246 is an information disclosure vulnerability in Microsoft Excel, Excel Viewer, and Microsoft Office that allows for the improper disclosure of memory contents. This vulnerability has a CVSS score of 5.5 (Medium), indicating a local attack vector with low complexity, requiring user interaction, and resulting in high confidentiality impact without affecting integrity or availability. While the EPSS score suggests it's more likely to be exploited than 94% of CVEs, there is no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed on the CISA KEV catalog. Community discussion and media coverage are minimal, with only one mention and one article found, respectively.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:excel:2010:sp2:*:*:*:*:*:* | ||
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:excel:2013:sp1:*:*:*:*:*:* | ||
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:excel:2013:sp1:*:*:rt:*:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:excel:2016:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:excel_viewer:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.