CVE-2018-0802

CVE: CVE-2018-0802
Published: 2018-01-10T01:29Z
Vendor: microsoft
Products: office
Versions: 2007, 2010, 2013, 2016,
office_compatibility_pack
Versions: -,
word
Versions: 2007, 2010, 2013, 2016,
Description Language: en
Description: Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due to the way objects are handled in memory, aka “Microsoft Office Memory Corruption Vulnerability”. This CVE is unique from CVE-2018-0797 and CVE-2018-0812.
References:
http://www.securityfocus.com/bid/102347
http://www.securitytracker.com/id/1040153
https://0patch.blogspot.com/2018/01/the-bug-that-killed-equation-editor-how.html
https://github.com/rxwx/CVE-2018-0802
https://github.com/zldww2011/CVE-2018-0802_POC
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0802