Exposure of Microsoft Excel

Editors
26
exposure score
134
sites use
1
exploited
0
critical
Vexday analysis

Com apenas 39 CVEs catalogadas, o Microsoft Excel apresenta volume relativamente contido de vulnerabilidades, mas sua taxa de exploração ativa está significativamente acima da média geral do catálogo — 5,7 vezes superior —, o que indica que as falhas historicamente identificadas nesta tecnologia tendem a ser aproveitadas na prática com frequência desproporcional. A CVE-2019-1297, a vulnerabilidade mais perigosa atualmente em exploração ativa, registra EPSS de 0,2046, sinalizando probabilidade não negligenciável de exploração observada em ambientes reais. O maior EPSS registrado entre as CVEs do produto chega a 0,28178, reforçando que ao menos parte do portfólio de vulnerabilidades continua relevante do ponto de vista operacional, mesmo sem registros de novas ocorrências nos últimos 90 dias. Equipes de segurança devem priorizar a verificação do status de correção das vulnerabilidades em KEV, dado o padrão histórico de exploração ativa acima da média.

CVEs

38 results
CVE-2018-8597—A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "EPSS 16.1%CVE-2018-8636—A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "EPSS 16.1%CVE-2020-0759—A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'EPSS 15.2%CVE-2019-1327—A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'EPSS 14.0%CVE-2019-0828—A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'EPSS 13.7%CVE-2019-1110—A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'EPSS 13.2%CVE-2019-1111—A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'EPSS 13.2%CVE-2018-8429—An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka "Microsoft Excel InEPSS 12.3%CVE-2018-8382—An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka "Microsoft Excel InEPSS 12.3%CVE-2020-0906—A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'EPSS 11.5%CVE-2019-1446—An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka 'Microsoft Excel InEPSS 8.9%CVE-2020-0760—A remote code execution vulnerability exists when Microsoft Office improperly loads arbitrary type libraries, aka 'Microsoft Office Remote CEPSS 8.8%CVE-2018-8627—An information disclosure vulnerability exists when Microsoft Excel software reads out of bound memory due to an uninitialized variable, whiEPSS 8.6%CVE-2019-1464—An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka 'Microsoft Excel InEPSS 8.1%CVE-2019-1263—An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka 'Microsoft Excel InEPSS 7.8%CVE-2019-0669—An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka 'Microsoft Excel InEPSS 6.4%CVE-2018-8598—An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka "Microsoft Excel InEPSS 6.2%CVE-2018-0907—Microsoft Excel 2007 SP3, Microsoft Excel 2010 SP2, Microsoft Excel 2013 SP1, Microsoft Excel 2016, Microsoft Office 2016 Click-to-Run and MEPSS 5.9%