CVE-2018-8539 is a remote code execution vulnerability in Microsoft Word that allows an attacker to execute arbitrary code when the software improperly handles objects in memory. This high-severity flaw (CVSS 7.8) primarily impacts Microsoft Office and SharePoint Server, requiring user interaction (e.g., opening a malicious document) for successful exploitation. While no public exploit code is readily available (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion and media coverage, indicating awareness. There is no evidence of active exploitation in the wild, and it is not listed on CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2010:sp2:*:*:*:*:*:* | ||
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:office_web_apps:2010:sp2:*:*:*:*:*:* | ||
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:sharepoint_server:2010:sp2:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.