Vulnerability CVE-2018-8412


Published: 2018-08-15

Description:
An elevation of privilege vulnerability exists when the Microsoft AutoUpdate (MAU) application for Mac improperly validates updates before executing them, aka "Microsoft (MAU) Office Elevation of Privilege Vulnerability." This affects Microsoft Office.

Type:

CWE-20

(Improper Input Validation)

CVSS2 => (AV:L/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4.6/10
6.4/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Microsoft -> Office for mac 

 References:
http://www.securityfocus.com/bid/105014
http://www.securitytracker.com/id/1041484
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8412

Copyright 2024, cxsecurity.com

 

Back to Top