HTTP: Microsoft Office Excel Note Record Information Disclosure

An information disclosure vulnerability has been reported in Microsoft Office Excel. A remote attacker could exploit this vulnerability by enticing a user to open a maliciously crafted Excel file. Successful exploitation would allow the attacker to disclose sensitive information that may help in further attacks.

Extended Description

An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka "Microsoft Excel Information Disclosure Vulnerability." This affects Microsoft Excel Viewer, Microsoft Office, Microsoft Excel.

Affected Products

Microsoft office_compatibility_pack

References

CVE: CVE-2018-8382

Short Name
HTTP:STC:DL:XLS-NOTE-RCRD-ID
Severity
Minor
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2018-8382 Disclosure Excel Information Microsoft Note Office Record
Release Date
11/13/2018
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3590
False Positive
Unknown
Vendors

Microsoft

CVSS Score

4.3

Found a potential security threat?