Vulnerability Details CVE-2018-0853
Microsoft Office 2010 SP2, Microsoft Office 2013 SP1 and RT SP1, Microsoft Office 2016, and Microsoft Office 2016 Click-to-Run (C2R) allow an information disclosure vulnerability, due to how Office initializes the affected variable, aka "Microsoft Office Information Disclosure Vulnerability".
Exploit prediction scoring system (EPSS) score
EPSS Score 0.117
EPSS Ranking 93.4%
CVSS Severity
CVSS v3 Score 3.3
CVSS v2 Score 4.3
Products affected by CVE-2018-0853
-
cpe:2.3:a:microsoft:office:2010
-
cpe:2.3:a:microsoft:office:2013
-
cpe:2.3:a:microsoft:office:2016