CVE-2018-0853: Microsoft Office

Low severity, CVSS 3.3. EPSS: 11.8% chance of exploitation in the next 30 days.

Microsoft Office 2010 SP2, Microsoft Office 2013 SP1 and RT SP1, Microsoft Office 2016, and Microsoft Office 2016 Click-to-Run (C2R) allow an information disclosure vulnerability, due to how Office initializes the affected variable, aka "Microsoft Office Information Disclosure Vulnerability".

Affected products

  • Microsoft Office: version 2010 only; version 2013 only; version 2016 only

Published 2018-02-15. Last modified 2026-06-17.