Description Preview
Microsoft Word in Microsoft Office 2007, 2010, 2013, and 2016 contains a remote code execution vulnerability due to the way objects are handled in memory. This flaw could allow a remote attacker to execute arbitrary code on a vulnerable system, potentially taking control of the affected machine. The vulnerability is distinct from CVE-2018-0792 and was publicly disclosed in January 2018.
Overview
This CVE identifies a remote code execution vulnerability in Microsoft Word across Office 2007 through 2016, arising from improper handling of objects in memory. Exploitation could enable an attacker to run arbitrary code on the victim’s system, potentially compromising confidentiality, integrity, and availability. The issue was made public in early 2018 and is distinct from CVE-2018-0792.
Remediation
- Apply the latest Microsoft Office security updates that address CVE-2018-0794. Use Windows Update or Office Update to ensure Word and related components are patched.
- Enable automatic updates for Office to receive future security fixes promptly.
- After patching, verify the Office build/version to confirm the remediation is in place.
- As a defense-in-depth measure, enable Protected View and restrict macros in Word documents to reduce exposure to untrusted content.
- Educate users to avoid opening untrusted or unexpected Word documents from unknown sources, and consider implementing email/file screening to filter malicious attachments.
References
- 102373 (BID): http://www.securityfocus.com/bid/102373
- 1040153 (SECTRACK): http://www.securitytracker.com/id/1040153
- MSRC Advisory: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0794
Industry ExposureMost to leastThis section illustrates the prevalence of a specific Common Vulnerabilities and Exposures (CVE) across various industries based on customer reports. The ranking displays industries from the most to least affected by this particular vulnerability, offering valuable insight into where this CVE has been most frequently observed. This information can help organizations within these sectors prioritize their security efforts, understand their relative risk exposure compared to their peers, and focus remediation strategies where they are most needed. By understanding the industry-specific impact, organizations can make more informed decisions regarding patching, resource allocation, and overall risk management related to this CVE.
This section illustrates the prevalence of a specific Common Vulnerabilities and Exposures (CVE) across various industries based on customer reports. The ranking displays industries from the most to least affected by this particular vulnerability, offering valuable insight into where this CVE has been most frequently observed. This information can help organizations within these sectors prioritize their security efforts, understand their relative risk exposure compared to their peers, and focus remediation strategies where they are most needed. By understanding the industry-specific impact, organizations can make more informed decisions regarding patching, resource allocation, and overall risk management related to this CVE.
- ManufacturingManufacturing: Medium
- Public AdministrationPublic Administration: Medium
- Health Care & Social AssistanceHealth Care & Social Assistance: Medium
- Transportation & WarehousingTransportation & Warehousing: Medium
- Educational ServicesEducational Services: Low
- Finance and InsuranceFinance and Insurance: Low
- Professional, Scientific, & Technical ServicesProfessional, Scientific, & Technical Services: Low
- Management of Companies & EnterprisesManagement of Companies & Enterprises: Low
- Other Services (except Public Administration)Other Services (except Public Administration): Low
- Retail TradeRetail Trade: Low
- Arts, Entertainment & RecreationArts, Entertainment & Recreation: Low
- UtilitiesUtilities: Low
- Real Estate Rental & LeasingReal Estate Rental & Leasing: Low
- Agriculture, Forestry Fishing & HuntingAgriculture, Forestry Fishing & Hunting: Low
- Accommodation & Food ServicesAccommodation & Food Services: Low
- Administrative, Support, Waste Management & Remediation ServicesAdministrative, Support, Waste Management & Remediation Services: Low
- ConstructionConstruction: Low
- InformationInformation: Low
- MiningMining: Low
- Wholesale TradeWholesale Trade: Low

