Endpoint Vulnerability

Microsoft Publisher Remote Code Execution Vulnerability

Description

A remote code execution vulnerability exists when Microsoft Publisher fails to utilize features that lock down the Local Machine zone when instantiating OLE objects. An attacker who successfully exploited the vulnerability could force arbitrary code to be executed in the Local Machine zone.

Affected Products

Microsoft Publisher 2010 Service Pack 2 (32-bit editions),Microsoft Publisher 2010 Service Pack 2 (64-bit editions)

References

CVE-2018-8245,