CVE-2018-1028 (CNNVD-201804-626)
中文标题:
Microsoft Office graphics 安全漏洞
英文标题:
A remote code execution vulnerability exists when the Office graphics component improperly handles s...
漏洞描述
中文描述:
Microsoft Excel Services等都是美国微软(Microsoft)公司的产品。Microsoft Excel Services是一套运行于企业业务协作平台用来加载、计算和显示Microsoft Excel的服务应用程序。Office 2010 SP2是一套办公软件套件产品。Office graphics是其中的一个图形组件。 Microsoft Office graphics组件中存在远程代码执行漏洞,该漏洞源于程序没有正确的处理特制的嵌入字体。远程攻击者可利用该漏洞在用户系统上执行任意代码。以下产品和版本受到影响:Microsoft Excel Services;Microsoft Office 2010 SP2,Microsoft Office 2013 RT SP1,Microsoft Office 2013 SP1,Microsoft Office 2016;Microsoft Office Web Apps 2010 SP2,Microsoft Office Web Apps Server 2013 SP1,Microsoft SharePoint Enterprise Server 2016,Microsoft SharePoint Server 2013 SP1;Word Automation Services。
英文描述:
A remote code execution vulnerability exists when the Office graphics component improperly handles specially crafted embedded fonts, aka "Microsoft Office Graphics Remote Code Execution Vulnerability." This affects Word, Microsoft Office, Microsoft SharePoint, Excel, Microsoft SharePoint Server.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| Microsoft | Word | Automation Services on Microsoft SharePoint Server 2010 Service Pack 2 | - | - |
cpe:2.3:a:microsoft:word:automation_services_on_microsoft_sharepoint_server_2010_service_pack_2:*:*:*:*:*:*:*
|
| Microsoft | Word | Automation Services on Microsoft SharePoint Server 2013 Service Pack 1 | - | - |
cpe:2.3:a:microsoft:word:automation_services_on_microsoft_sharepoint_server_2013_service_pack_1:*:*:*:*:*:*:*
|
| Microsoft | Microsoft Office | 2010 Service Pack 2 (32-bit editions) | - | - |
cpe:2.3:a:microsoft:microsoft_office:2010_service_pack_2_(32-bit_editions):*:*:*:*:*:*:*
|
| Microsoft | Microsoft Office | 2010 Service Pack 2 (64-bit editions) | - | - |
cpe:2.3:a:microsoft:microsoft_office:2010_service_pack_2_(64-bit_editions):*:*:*:*:*:*:*
|
| Microsoft | Microsoft Office | 2013 RT Service Pack 1 | - | - |
cpe:2.3:a:microsoft:microsoft_office:2013_rt_service_pack_1:*:*:*:*:*:*:*
|
| Microsoft | Microsoft Office | 2013 Service Pack 1 (32-bit editions) | - | - |
cpe:2.3:a:microsoft:microsoft_office:2013_service_pack_1_(32-bit_editions):*:*:*:*:*:*:*
|
| Microsoft | Microsoft Office | 2013 Service Pack 1 (64-bit editions) | - | - |
cpe:2.3:a:microsoft:microsoft_office:2013_service_pack_1_(64-bit_editions):*:*:*:*:*:*:*
|
| Microsoft | Microsoft Office | 2016 (32-bit edition) | - | - |
cpe:2.3:a:microsoft:microsoft_office:2016_(32-bit_edition):*:*:*:*:*:*:*
|
| Microsoft | Microsoft Office | 2016 (64-bit edition) | - | - |
cpe:2.3:a:microsoft:microsoft_office:2016_(64-bit_edition):*:*:*:*:*:*:*
|
| Microsoft | Microsoft Office | Web Apps 2010 Service Pack 2 | - | - |
cpe:2.3:a:microsoft:microsoft_office:web_apps_2010_service_pack_2:*:*:*:*:*:*:*
|
| Microsoft | Microsoft Office | Web Apps Server 2013 Service Pack 1 | - | - |
cpe:2.3:a:microsoft:microsoft_office:web_apps_server_2013_service_pack_1:*:*:*:*:*:*:*
|
| Microsoft | Microsoft SharePoint | Enterprise Server 2016 | - | - |
cpe:2.3:a:microsoft:microsoft_sharepoint:enterprise_server_2016:*:*:*:*:*:*:*
|
| Microsoft | Excel | Services on Microsoft SharePoint Enterprise Server 2013 Service Pack 1 | - | - |
cpe:2.3:a:microsoft:excel:services_on_microsoft_sharepoint_enterprise_server_2013_service_pack_1:*:*:*:*:*:*:*
|
| Microsoft | Microsoft SharePoint Server | 2013 Service Pack 1 | - | - |
cpe:2.3:a:microsoft:microsoft_sharepoint_server:2013_service_pack_1:*:*:*:*:*:*:*
|
| microsoft | excel_services | - | - | - |
cpe:2.3:a:microsoft:excel_services:-:*:*:*:*:*:*:*
|
| microsoft | office | 2013 | - | - |
cpe:2.3:a:microsoft:office:2013:sp1:*:*:*:*:*:*
|
| microsoft | office | 2013_rt | - | - |
cpe:2.3:a:microsoft:office:2013_rt:sp1:*:*:*:*:*:*
|
| microsoft | office | 2016 | - | - |
cpe:2.3:a:microsoft:office:2016:*:*:*:*:*:*:*
|
| microsoft | office_2010 | * | - | - |
cpe:2.3:a:microsoft:office_2010:*:sp2:*:*:*:*:*:*
|
| microsoft | office_web_apps | 2010 | - | - |
cpe:2.3:a:microsoft:office_web_apps:2010:sp2:*:*:*:*:*:*
|
| microsoft | office_web_apps | 2013 | - | - |
cpe:2.3:a:microsoft:office_web_apps:2013:sp1:*:*:*:*:*:*
|
| microsoft | sharepoint_enterprise_server | 2013 | - | - |
cpe:2.3:a:microsoft:sharepoint_enterprise_server:2013:sp1:*:*:*:*:*:*
|
| microsoft | sharepoint_enterprise_server | 2016 | - | - |
cpe:2.3:a:microsoft:sharepoint_enterprise_server:2016:*:*:*:*:*:*:*
|
| microsoft | word_automation_services | - | - | - |
cpe:2.3:a:microsoft:word_automation_services:-:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2018-1028 |
2025-11-11 15:19:46 | 2025-11-11 07:34:59 |
| NVD | nvd_CVE-2018-1028 |
2025-11-11 14:55:53 | 2025-11-11 07:43:35 |
| CNNVD | cnnvd_CNNVD-201804-626 |
2025-11-11 15:10:00 | 2025-11-11 07:53:41 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 代码注入
- cnnvd_id: 未提取 -> CNNVD-201804-626
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- severity: SeverityLevel.MEDIUM -> SeverityLevel.HIGH
- cvss_score: 未提取 -> 8.8
- cvss_vector: NOT_EXTRACTED -> CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- cvss_version: NOT_EXTRACTED -> 3.0
- affected_products_count: 14 -> 24
- data_sources: ['cve'] -> ['cve', 'nvd']