CVE-2018-8558 is an information disclosure vulnerability affecting Microsoft Office and Office 365 ProPlus. It occurs when Microsoft Outlook fails to enforce "Default link type" settings configured in the SharePoint Online Admin Center, potentially exposing sensitive information. Rated 6.5 Medium on the CVSS scale, this vulnerability allows an unauthenticated attacker to achieve high confidentiality impact with low attack complexity, requiring no user interaction. There is no evidence of active exploitation, public exploit code, or Metasploit modules, and it is not listed in CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2019CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2019:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:office_365_proplus:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.