The Windows Graphics Component in Microsoft Office 2007 SP3; 2010 SP2; and Word Viewer; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Live Meeting 2007; Silverlight 5; Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; and Windows 7 SP1 allows remote attackers to execute arbitrary code via a crafted web site, aka "Graphics Component Remote Code Execution Vulnerability." This vulnerability is different from that described in CVE-2017-0014.
2017-03-17T00:59:02.917
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 7.8 (HIGH)
AV:N/AC:M/Au:N/C:C/I:C/A:C
8.6
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | microsoft | live_meeting | 2007 | Yes |
Application | microsoft | lync | 2010 | Yes |
Application | microsoft | lync | 2013 | Yes |
Application | microsoft | office | 2007 | Yes |
Application | microsoft | office | 2010 | Yes |
Application | microsoft | silverlight | 5.0 | Yes |
Application | microsoft | skype_for_business | 2016 | Yes |
Application | microsoft | word_viewer | - | Yes |
Operating System | microsoft | windows_7 | - | Yes |
Operating System | microsoft | windows_server_2008 | - | Yes |
Operating System | microsoft | windows_server_2008 | r2 | Yes |
Operating System | microsoft | windows_vista | - | Yes |