The Vigil@nce team watches public vulnerabilities impacting your computers, and then offers security solutions, a database and tools to fix them.

Computer vulnerabilities of Office

cybersecurity bulletin CVE-2018-8176 CVE-2018-8244 CVE-2018-8245

Microsoft Office: vulnerabilities of June 2018

Synthesis of the vulnerability

An attacker can use several vulnerabilities of Microsoft products.
Severity: 3/4.
Number of vulnerabilities in this bulletin: 8.
Creation date: 13/06/2018.
Identifiers: CERTFR-2018-AVI-285, CVE-2018-8176, CVE-2018-8244, CVE-2018-8245, CVE-2018-8246, CVE-2018-8247, CVE-2018-8248, CVE-2018-8252, CVE-2018-8254, VIGILANCE-VUL-26396, ZDI-18-593.
Full Vigil@nce bulletin... (Free trial)

Description of the vulnerability

An attacker can use several vulnerabilities of Microsoft products.

The document located in information sources was generated by Vigil@nce from the Microsoft database. It contains details for each product.
Full Vigil@nce bulletin... (Free trial)

weakness alert CVE-2017-17688 CVE-2017-17689

Outlook Gpg4win, Thunderbird Enigmail: PGP and S/MIME decryption

Synthesis of the vulnerability

An attacker can use Outlook Gpg4win or Thunderbird Enigmail, in order to obtain sensitive information.
Severity: 3/4.
Number of vulnerabilities in this bulletin: 2.
Creation date: 14/05/2018.
Revision date: 14/05/2018.
Identifiers: CERTFR-2018-ALE-007, CVE-2017-17688, CVE-2017-17689, DSA-4244-1, FEDORA-2018-1f651350de, FEDORA-2018-25525a9346, FEDORA-2018-6020628437, FEDORA-2018-73e30969a4, FEDORA-2018-77fe2e20ad, FEDORA-2018-e6ee09fc50, openSUSE-SU-2018:1329-1, openSUSE-SU-2018:1330-1, openSUSE-SU-2018:1347-1, openSUSE-SU-2018:1392-1, openSUSE-SU-2018:1393-1, openSUSE-SU-2018:1451-1, openSUSE-SU-2018:1454-1, SSA:2018-191-01, VIGILANCE-VUL-26123, VU#122919.
Full Vigil@nce bulletin... (Free trial)

Description of the vulnerability

Plugins can be installed to automatically decrypt received emails encrypted with PGP or S/MIME:
 - Apple Mail : GPGTools
 - IBM Notes : PGP Lotus Notes Plug-In
 - Outlook : Gpg4win
 - Thunderbird : Enigmail
 - etc.

However, an attacker who has an encrypted email can use these plugins in order to decrypt it, for example using an image in an HTML email.

An attacker can therefore use Outlook Gpg4win or Thunderbird Enigmail, in order to obtain sensitive information.
Full Vigil@nce bulletin... (Free trial)

threat note CVE-2018-8147 CVE-2018-8148 CVE-2018-8149

Microsoft Office: vulnerabilities of May 2018

Synthesis of the vulnerability

An attacker can use several vulnerabilities of Microsoft products.
Severity: 3/4.
Number of vulnerabilities in this bulletin: 14.
Creation date: 09/05/2018.
Identifiers: CERTFR-2018-AVI-252, CVE-2018-8147, CVE-2018-8148, CVE-2018-8149, CVE-2018-8150, CVE-2018-8155, CVE-2018-8156, CVE-2018-8157, CVE-2018-8158, CVE-2018-8160, CVE-2018-8161, CVE-2018-8162, CVE-2018-8163, CVE-2018-8168, CVE-2018-8176, VIGILANCE-VUL-26060, ZDI-18-430, ZDI-18-431, ZDI-18-432.
Full Vigil@nce bulletin... (Free trial)

Description of the vulnerability

An attacker can use several vulnerabilities of Microsoft products.

The document located in information sources was generated by Vigil@nce from the Microsoft database. It contains details for each product.
Full Vigil@nce bulletin... (Free trial)

computer vulnerability bulletin CVE-2018-0920 CVE-2018-0950 CVE-2018-1005

Office: vulnerabilities of April 2018

Synthesis of the vulnerability

An attacker can use several vulnerabilities of Microsoft products.
Severity: 3/4.
Number of vulnerabilities in this bulletin: 13.
Creation date: 11/04/2018.
Identifiers: CERTFR-2018-AVI-179, CVE-2018-0920, CVE-2018-0950, CVE-2018-1005, CVE-2018-1007, CVE-2018-1011, CVE-2018-1014, CVE-2018-1026, CVE-2018-1027, CVE-2018-1028, CVE-2018-1029, CVE-2018-1030, CVE-2018-1032, CVE-2018-1034, VIGILANCE-VUL-25832, VU#974272, ZDI-18-292.
Full Vigil@nce bulletin... (Free trial)

Description of the vulnerability

An attacker can use several vulnerabilities of Microsoft products.

The document located in information sources was generated by Vigil@nce from the Microsoft database. It contains details for each product.
Full Vigil@nce bulletin... (Free trial)

security alert CVE-2018-0903 CVE-2018-0907 CVE-2018-0909

Microsoft Office: vulnerabilities of March 2018

Synthesis of the vulnerability

An attacker can use several vulnerabilities of Microsoft products.
Severity: 4/4.
Number of vulnerabilities in this bulletin: 17.
Creation date: 14/03/2018.
Identifiers: CERTFR-2018-AVI-130, CVE-2018-0903, CVE-2018-0907, CVE-2018-0909, CVE-2018-0910, CVE-2018-0911, CVE-2018-0912, CVE-2018-0913, CVE-2018-0914, CVE-2018-0915, CVE-2018-0916, CVE-2018-0917, CVE-2018-0919, CVE-2018-0921, CVE-2018-0922, CVE-2018-0923, CVE-2018-0944, CVE-2018-0947, VIGILANCE-VUL-25541.
Full Vigil@nce bulletin... (Free trial)

Description of the vulnerability

An attacker can use several vulnerabilities of Microsoft products.

The document located in information sources was generated by Vigil@nce from the Microsoft database. It contains details for each product.
Full Vigil@nce bulletin... (Free trial)

weakness announce CVE-2018-0789 CVE-2018-0790 CVE-2018-0791

Microsoft Office: vulnerabilities of January 2018

Synthesis of the vulnerability

An attacker can use several vulnerabilities of Microsoft products.
Severity: 3/4.
Number of vulnerabilities in this bulletin: 19.
Creation date: 10/01/2018.
Revision date: 22/02/2018.
Identifiers: CERTFR-2018-AVI-021, CVE-2018-0789, CVE-2018-0790, CVE-2018-0791, CVE-2018-0792, CVE-2018-0793, CVE-2018-0794, CVE-2018-0795, CVE-2018-0796, CVE-2018-0797, CVE-2018-0798, CVE-2018-0799, CVE-2018-0801, CVE-2018-0802, CVE-2018-0804, CVE-2018-0805, CVE-2018-0806, CVE-2018-0807, CVE-2018-0812, CVE-2018-0819, VIGILANCE-VUL-24992, ZDI-18-161.
Full Vigil@nce bulletin... (Free trial)

Description of the vulnerability

An attacker can use several vulnerabilities of Microsoft products.

The document located in information sources was generated by Vigil@nce from the Microsoft database. It contains details for each product.
Full Vigil@nce bulletin... (Free trial)

computer vulnerability announce CVE-2018-0841 CVE-2018-0850 CVE-2018-0851

Microsoft Office: vulnerabilities of February 2018

Synthesis of the vulnerability

An attacker can use several vulnerabilities of Microsoft products.
Severity: 3/4.
Number of vulnerabilities in this bulletin: 7.
Creation date: 14/02/2018.
Identifiers: CERTFR-2018-AVI-086, CVE-2018-0841, CVE-2018-0850, CVE-2018-0851, CVE-2018-0852, CVE-2018-0853, CVE-2018-0864, CVE-2018-0869, VIGILANCE-VUL-25293, ZDI-18-219.
Full Vigil@nce bulletin... (Free trial)

Description of the vulnerability

An attacker can use several vulnerabilities of Microsoft products.

The document located in information sources was generated by Vigil@nce from the Microsoft database. It contains details for each product.
Full Vigil@nce bulletin... (Free trial)

security weakness CVE-2018-0845 CVE-2018-0848 CVE-2018-0849

Microsoft Office: vulnerabilities of February 2018

Synthesis of the vulnerability

An attacker can use several vulnerabilities of Microsoft Office.
Severity: 3/4.
Number of vulnerabilities in this bulletin: 4.
Creation date: 07/02/2018.
Identifiers: CVE-2018-0845, CVE-2018-0848, CVE-2018-0849, CVE-2018-0862, VIGILANCE-VUL-25236.
Full Vigil@nce bulletin... (Free trial)

Description of the vulnerability

An attacker can use several vulnerabilities of Microsoft Office.
Full Vigil@nce bulletin... (Free trial)

computer threat note CVE-2017-11934 CVE-2017-11935 CVE-2017-11936

Microsoft Office: vulnerabilities of December 2017

Synthesis of the vulnerability

An attacker can use several vulnerabilities of Microsoft products.
Severity: 3/4.
Number of vulnerabilities in this bulletin: 4.
Creation date: 13/12/2017.
Identifiers: CERTFR-2017-AVI-466, CVE-2017-11934, CVE-2017-11935, CVE-2017-11936, CVE-2017-11939, VIGILANCE-VUL-24756.
Full Vigil@nce bulletin... (Free trial)

Description of the vulnerability

An attacker can use several vulnerabilities of Microsoft products.

The document located in information sources was generated by Vigil@nce from the Microsoft database. It contains details for each product.
Full Vigil@nce bulletin... (Free trial)

security weakness 24664

Mail client: sender spoofing via Mailsploit

Synthesis of the vulnerability

An attacker can send an email with a special From header, which is truncated by some mail clients, in order to deceive the victim.
Severity: 3/4.
Creation date: 06/12/2017.
Identifiers: CERTFR-2017-ALE-019, Mailsploit, MFSA-2017-30, Synology-SA-17:82, VIGILANCE-VUL-24664.
Full Vigil@nce bulletin... (Free trial)

Description of the vulnerability

Messaging clients interpret the From header to display the sender name.

However, using a Base64 or Quoted Printable encoding, and '\0' or '\n' characters, an attacker can force the displayed email address to be truncated.

An attacker can therefore send an email with a special From header, which is truncated by some mail clients, in order to deceive the victim.
Full Vigil@nce bulletin... (Free trial)
Our database contains other pages. You can request a free trial to read them.

Display information about Office: