← Vulnerability feed

Vulnerability record · CVE-2018-8176 · published 23 May 2018

CVE-2018-8176: Microsoft office for mac improper input validation vulnerability

Microsoft · Office For Mac

A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly validate XML content, aka "Microsoft PowerPoint Remote Code Execution Vulnerability." This affects Microsoft Office.

8.8 CVSS 3.0 High EPSS 24% · top 2.2% CWE-20 · Improper input validation
8.8CVSS 3.0 base score, v2 9.3
24%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly validate XML content, aka "Microsoft PowerPoint Remote Code Execution Vulnerability." This affects Microsoft Office.

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-8176 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2018-8332Microsoft office vulnerabilityA remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Win32k Graphics …EPSS 19%7.8CVE-2018-8412Microsoft office for mac improper input validation vulnerabilityAn elevation of privilege vulnerability exists when the Microsoft AutoUpdate (MAU) application for Mac improperly validates updates before executing …EPSS 1.2%7.8CVE-2018-8147Microsoft excel vulnerabilityA remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft…EPSS 25%7.8CVE-2018-8148Microsoft excel vulnerabilityA remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft…EPSS 25%7.8CVE-2018-8162Microsoft excel vulnerabilityA remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft…EPSS 25%7.8CVE-2017-11825Microsoft office memory buffer overflow vulnerabilityMicrosoft Office 2016 Click-to-Run (C2R) and Microsoft Office 2016 for Mac allow an attacker to use a specially crafted file to perform actions in th…EPSS 23%7.1CVE-2016-7276Microsoft office out-of-bounds read vulnerabilityMicrosoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office for Mac 2011, and Office 2016 for Mac allow remote attackers to obtain sensitive …EPSS 25%6.5CVE-2016-7257Microsoft office for mac information exposure vulnerabilityThe GDI component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Office for Mac 2011, and Office 2016 for Mac all…EPSS 23%

Source: NIST National Vulnerability Database (record CVE-2018-8176), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.