Remote Code Execution Vulnerability in Microsoft Windows and Office Products
CVE-2017-8682

8.8HIGH

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
13 September 2017

Summary

This vulnerability allows an attacker to execute arbitrary code on affected systems through maliciously crafted embedded fonts within documents. The exploit can take advantage of the way Windows graphics components interact with these fonts, potentially leading to unauthorized actions being executed on the victim's system. Users are urged to apply the latest patches and updates to mitigate the risk of exploitation.

Affected Version(s)

Windows graphics Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, Windows Server 2016, Microsoft Office Word Viewer, Microsoft Office 2007 Service Pack 3 , and Microsoft Office 2010 Service Pack 2

References

EPSS Score

23% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.