Security News > 2018 > January > Microsoft plugs 56 vulns, including Office flaw exploited in attacks

Microsoft plugs 56 vulns, including Office flaw exploited in attacks
2018-01-10 20:51

As part of the January 2018 Patch Tuesday, Microsoft has released fixes for 56 CVE-listed vulnerabilities, including the Meltdown and Spectre flaws, and an Office bug actively exploited by attackers. Office flaw exploited in the wild Security updates and patches for mitigating the risk of Meltdown and Spectre attacks have received much attention in the past days, but those released by Microsoft on Tuesday also deserve it. As mentioned earlier, a flaw (CVE-2018-0802) in Microsoft … More →


News URL

http://feedproxy.google.com/~r/HelpNetSecurity/~3/PwqzHPXtZKg/

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2018-01-10 CVE-2018-0802 Out-of-bounds Write vulnerability in Microsoft Office, Office Compatibility Pack and Word
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Office Memory Corruption Vulnerability".
local
low complexity
microsoft CWE-787
7.8

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Microsoft 480 75 2308 5127 264 7774