CVE-2017-11878
Microsoft Office Excel Workbook Use-After-Free Remote Code Execution Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Microsoft Excel 2007 Service Pack 3, Microsoft Excel 2010 Service Pack 2, Microsoft Excel 2013 Service Pack 1, Microsoft Excel 2013 RT Service Pack 1, Microsoft Excel 2016, Microsoft Office Compatibility Pack Service Pack 3, and Microsoft Excel Viewer 2007 Service Pack 3 allow an attacker to run arbitrary code in the context of the current user by failing to properly handle objects in memory, aka "Microsoft Excel Memory Corruption Vulnerability".
Microsoft Excel 2007 Service Pack 3, Microsoft Excel 2010 Service Pack 2, Microsoft Excel 2013 Service Pack 1, Microsoft Excel 2013 RT Service Pack 1, Microsoft Excel 2016, Microsoft Office Compatibility Pack Service Pack 3 y Microsoft Excel Viewer 2007 Service Pack 3 permiten que un atacante ejecute código arbitrario en el contexto del usuario actual cuando no se gestionan correctamente los objetos en la memoria. Esto también se conoce como "Microsoft Excel Memory Corruption Vulnerability".
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Office Excel. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the handling of Excel workbooks. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code under the context of the process.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-07-31 CVE Reserved
- 2017-11-15 CVE Published
- 2024-03-31 EPSS Updated
- 2024-09-17 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/101756 | Third Party Advisory | |
http://www.securitytracker.com/id/1039783 | Issue Tracking |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11878 | 2023-10-03 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Microsoft Search vendor "Microsoft" | Excel Search vendor "Microsoft" for product "Excel" | 2007 Search vendor "Microsoft" for product "Excel" and version "2007" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Excel Search vendor "Microsoft" for product "Excel" | 2010 Search vendor "Microsoft" for product "Excel" and version "2010" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Excel Search vendor "Microsoft" for product "Excel" | 2013 Search vendor "Microsoft" for product "Excel" and version "2013" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Excel Search vendor "Microsoft" for product "Excel" | 2013 Search vendor "Microsoft" for product "Excel" and version "2013" | sp1 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Excel Search vendor "Microsoft" for product "Excel" | 2016 Search vendor "Microsoft" for product "Excel" and version "2016" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Excel Viewer Search vendor "Microsoft" for product "Excel Viewer" | 2007 Search vendor "Microsoft" for product "Excel Viewer" and version "2007" | sp3 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Office Compatibility Pack Search vendor "Microsoft" for product "Office Compatibility Pack" | - | sp3 |
Affected
|