CVE-2018-8432: Microsoft Excel Viewer
High severity, CVSS 7.8. EPSS: 19.5% chance of exploitation in the next 30 days.
A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka "Microsoft Graphics Components Remote Code Execution Vulnerability." This affects Windows 7, Microsoft Office, Microsoft Office Word Viewer, Office 365 ProPlus, Microsoft Excel Viewer, Microsoft PowerPoint Viewer, Windows Server 2019, Windows Server 2008 R2, Windows 10, Windows Server 2008.
Affected products
- Microsoft Excel Viewer: version 2007 only
- Microsoft Office: version 2016 only; version 2019 only
- Microsoft Office 365 Proplus: affected versions not specified
- Microsoft Office Compatibility Pack: affected versions not specified
- Microsoft PowerPoint Viewer: version 2007 only
- Microsoft Windows 10: version 1809 only
- Microsoft Windows 7: affected versions not specified
- Microsoft Windows Server 2008: affected versions not specified; version r2 only
- Microsoft Windows Server 2019: affected versions not specified
- Microsoft Word Viewer: affected versions not specified
Published 2018-10-10. Last modified 2026-06-17.