Remote Code Execution Vulnerability in Microsoft Windows and Office Products
CVE-2017-8528

8.8HIGH

Key Information:

Vendor
Microsoft
Status
Vendor
CVE Published:
15 June 2017

Summary

A remote code execution vulnerability exists in Uniscribe, a component of the Windows operating system, and Microsoft Office applications. This issue arises from improper handling of objects in memory, allowing an attacker to execute arbitrary code on the affected systems. Successful exploitation can lead to full system compromise, potentially resulting in unauthorized access to sensitive information or system control. Affected versions include various iterations of Windows and Microsoft Office from Windows 7 SP1 to Windows 10 and Office 2007 to 2010.

Affected Version(s)

Uniscribe Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, Windows Server 2016, Microsoft Office 2007 SP3, and Microsoft Office 2010 SP2.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.