CVE-2017-8696
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Windows Uniscribe in Microsoft Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Office 2007 SP3; Office 2010 SP2; Word Viewer; Office for Mac 2011 and 2016; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Lync 2010 Attendee; and Live Meeting 2007 Add-in and Console allows an attacker to execute code remotely via a specially crafted website or a specially crafted document or email attachment, aka "Microsoft Graphics Component Remote Code Execution."
El componente Uniscribe de Windows en Microsoft Windows Server 2008 SP2 y R2 SP1; Windows 7 SP1; Office 2007 SP3; Office 2010 SP2; Word Viewer; Office for Mac 2011 y 2016; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Lync 2010 Attendee y Live Meeting 2007 Add-in y Console permite que un atacante ejecute código remotamente mediante una página web, un documento o archivo de correo adjunto especialmente manipulados. Esto también se conoce como "Microsoft Graphics Component Remote Code Execution".
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-05-03 CVE Reserved
- 2017-09-13 CVE Published
- 2024-01-28 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/100780 | Third Party Advisory | |
http://www.securitytracker.com/id/1039344 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8696 | 2017-09-21 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Microsoft Search vendor "Microsoft" | Live Meeting Search vendor "Microsoft" for product "Live Meeting" | 2007 Search vendor "Microsoft" for product "Live Meeting" and version "2007" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Lync Search vendor "Microsoft" for product "Lync" | 2010 Search vendor "Microsoft" for product "Lync" and version "2010" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Lync Search vendor "Microsoft" for product "Lync" | 2010 Search vendor "Microsoft" for product "Lync" and version "2010" | attendee |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Lync Search vendor "Microsoft" for product "Lync" | 2013 Search vendor "Microsoft" for product "Lync" and version "2013" | sp1 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Office 2007 Search vendor "Microsoft" for product "Office 2007" | - | sp3 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Office 2010 Search vendor "Microsoft" for product "Office 2010" | * | sp2 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Office Web Apps Search vendor "Microsoft" for product "Office Web Apps" | 2010 Search vendor "Microsoft" for product "Office Web Apps" and version "2010" | sp2 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Office Word Viewer Search vendor "Microsoft" for product "Office Word Viewer" | - | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Skype For Business Search vendor "Microsoft" for product "Skype For Business" | 2016 Search vendor "Microsoft" for product "Skype For Business" and version "2016" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 7 Search vendor "Microsoft" for product "Windows 7" | * | sp1 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows Server 2008 Search vendor "Microsoft" for product "Windows Server 2008" | * | sp2 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows Server 2008 Search vendor "Microsoft" for product "Windows Server 2008" | - | sp2 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows Server 2008 Search vendor "Microsoft" for product "Windows Server 2008" | r2 Search vendor "Microsoft" for product "Windows Server 2008" and version "r2" | sp1 |
Affected
|