9.3
CVE-2017-8570
- EPSS 94.25%
- Veröffentlicht 11.07.2017 21:29:01
- Zuletzt bearbeitet 22.10.2025 00:16:12
- Quelle secure@microsoft.com
- CVE-Watchlists
- Unerledigt
Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Microsoft Office Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0243.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
25.02.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog
Microsoft Office Remote Code Execution Vulnerability
SchwachstelleA remote code execution vulnerability exists in Microsoft Office software when it fails to properly handle objects in memory.
BeschreibungApply updates per vendor instructions.
Erforderliche Maßnahmen| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 94.25% | 0.999 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 9.3 | 8.6 | 10 |
AV:N/AC:M/Au:N/C:C/I:C/A:C
|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|