CVE-2018-8281
Estado: ModificadaAlta (7.8)—
A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka "Microsoft Office Remote Code Execution Vulnerability." This affects Microsoft Excel Viewer, Microsoft PowerPoint Viewer, Microsoft Office, Microsoft Office Word Viewer.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Puntuación base: 7.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 21%
- Percentil entre todas las CVEs puntuadas: 97
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (4)
CWE
- NVD-CWE-noinfo
Referencias
- http://www.securityfocus.com/bid/104609
- http://www.securitytracker.com/id/1041252
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8281
- http://www.securityfocus.com/bid/104609
- http://www.securitytracker.com/id/1041252
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8281
JSON original (NVD)
Mostrar
{
"id": "CVE-2018-8281",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 9.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "secure@microsoft.com",
"affectedData": [
{
"vendor": "Microsoft",
"product": "Microsoft Excel Viewer",
"versions": [
{
"status": "affected",
"version": "Microsoft Excel Viewer"
}
]
},
{
"vendor": "Microsoft",
"product": "Microsoft PowerPoint Viewer",
"versions": [
{
"status": "affected",
"version": "Microsoft PowerPoint Viewer"
}
]
},
{
"vendor": "Microsoft",
"product": "Microsoft Office",
"versions": [
{
"status": "affected",
"version": "2016 Click-to-Run (C2R) for 32-bit editions"
},
{
"status": "affected",
"version": "2016 Click-to-Run (C2R) for 64-bit editions"
},
{
"status": "affected",
"version": "2016 for Mac"
},
{
"status": "affected",
"version": "Compatibility Pack Service Pack 3"
}
]
},
{
"vendor": "Microsoft",
"product": "Microsoft Office Word Viewer",
"versions": [
{
"status": "affected",
"version": "Microsoft Office Word Viewer"
}
]
}
]
}
],
"published": "2018-07-11T00:29:01.070",
"references": [
{
"url": "http://www.securityfocus.com/bid/104609",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "secure@microsoft.com"
},
{
"url": "http://www.securitytracker.com/id/1041252",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "secure@microsoft.com"
},
{
"url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8281",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "secure@microsoft.com"
},
{
"url": "http://www.securityfocus.com/bid/104609",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id/1041252",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8281",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka \"Microsoft Office Remote Code Execution Vulnerability.\" This affects Microsoft Excel Viewer, Microsoft PowerPoint Viewer, Microsoft Office, Microsoft Office Word Viewer."
},
{
"lang": "es",
"value": "Existe una vulnerabilidad de ejecución remota de código en el software de Microsoft Office cuando no gestiona correctamente objetos en la memoria. Esto también se conoce como \"Microsoft Office Remote Code Execution Vulnerability\". Esto afecta a Microsoft Excel Viewer, Microsoft PowerPoint Viewer, Microsoft Office y Microsoft Office Word Viewer."
}
],
"lastModified": "2026-06-17T02:04:33.100",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:microsoft:office:2016:*:*:*:*:mac_os:*:*",
"vulnerable": true,
"matchCriteriaId": "A1A868C4-0A58-4660-9492-1BADD99D8E59"
},
{
"criteria": "cpe:2.3:a:microsoft:office:2016:*:*:*:click-to-run:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E74CB3D6-B0D7-4A6C-ABAA-170C7710D856"
},
{
"criteria": "cpe:2.3:a:microsoft:office_compatibility_pack:-:sp3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "71AF058A-2E5D-4B11-88DB-8903C64B13C1"
},
{
"criteria": "cpe:2.3:a:microsoft:office_powerpoint_viewer:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D7CAF125-B409-4209-AAF9-7EB795F09280"
},
{
"criteria": "cpe:2.3:a:microsoft:office_word_viewer:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C64B2636-8F96-48BA-921F-A8FA0E62DE63"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "secure@microsoft.com"
}