Apr 2018:
CVE-2018-0950 Published on April 12, 2018
An information disclosure vulnerability exists when Office renders Rich Text Format (RTF) email messages containing OLE objects when a message is opened or previewed, aka "Microsoft Office Information Disclosure Vulnerability." This affects Microsoft Word, Microsoft Office. This CVE ID is unique from CVE-2018-1007.
Products Associated with CVE-2018-0950
Want to know whenever a new CVE is published for Microsoft products? stack.watch will email you.
Affected Versions
Microsoft Word:- Version 2007 Service Pack 3 is affected.
- Version 2010 Service Pack 2 (32-bit editions) is affected.
- Version 2010 Service Pack 2 (64-bit editions) is affected.
- Version 2013 RT Service Pack 1 is affected.
- Version 2013 Service Pack 1 (32-bit editions) is affected.
- Version 2013 Service Pack 1 (64-bit editions) is affected.
- Version 2016 (32-bit edition) is affected.
- Version 2016 (64-bit edition) is affected.
- Version 2010 Service Pack 2 (32-bit editions) is affected.
- Version 2010 Service Pack 2 (64-bit editions) is affected.
- Version 2016 Click-to-Run (C2R) for 32-bit editions is affected.
- Version 2016 Click-to-Run (C2R) for 64-bit editions is affected.
- Version Compatibility Pack Service Pack 3 is affected.
Exploit Probability
EPSS
10.72%
Percentile
93.22%
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.