9.3

CVE-2017-8570

Warnung
Exploit
Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Microsoft Office Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0243.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Office Version 2007 Update sp3
Microsoft ≫ Office Version 2010 Update sp2
Microsoft ≫ Office Version 2013 Update sp1
Microsoft ≫ Office Version 2013 Update sp1 SwEdition rt
Microsoft ≫ Office Version 2016 HwPlatform x64
Microsoft ≫ Office Version 2016 HwPlatform x86

25.02.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog

Microsoft Office Remote Code Execution Vulnerability

Schwachstelle

A remote code execution vulnerability exists in Microsoft Office software when it fails to properly handle objects in memory.

Beschreibung

Apply updates per vendor instructions.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 85.61% 0.997
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
NIST 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CISA-ADP 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.securityfocus.com/bid/99445
Third Party Advisory
Broken Link
VDB Entry
https://github.com/ParsingTeam/ppsx-file-generator
Third Party Advisory
Exploit
https://github.com/rxwx/CVE-2017-8570
Third Party Advisory
https://github.com/tezukanice/Office8570
Third Party Advisory
Exploit
https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2017-8570
Patch
Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-8570
US Government Resource