Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2017-8696


Windows Uniscribe in Microsoft Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Office 2007 SP3; Office 2010 SP2; Word Viewer; Office for Mac 2011 and 2016; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Lync 2010 Attendee; and Live Meeting 2007 Add-in and Console allows an attacker to execute code remotely via a specially crafted website or a specially crafted document or email attachment, aka "Microsoft Graphics Component Remote Code Execution."


Published

2017-09-13T01:29:10.380

Last Modified

2025-04-20T01:37:25.860

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:H/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: HIGH
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

4.9

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-119

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application microsoft live_meeting 2007 Yes
Application microsoft lync 2010 Yes
Application microsoft lync 2010 Yes
Application microsoft lync 2013 Yes
Application microsoft office_2007 - Yes
Application microsoft office_2010 * Yes
Application microsoft office_web_apps 2010 Yes
Application microsoft office_word_viewer - Yes
Application microsoft skype_for_business 2016 Yes
Operating System microsoft windows_7 * Yes
Operating System microsoft windows_server_2008 * Yes
Operating System microsoft windows_server_2008 - Yes
Operating System microsoft windows_server_2008 r2 Yes

References