CVE-2017-0014Corporation Windows Graphics Component vulnerability

7 documents5 sources
Severity
7.5HIGHNVD
EPSS
23.8%
top 3.99%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 17
Latest updateMay 13

Description

The Windows Graphics Component in Microsoft Office 2010 SP2; Windows Server 2008 R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via a crafted web site, aka "Windows Graphics Component Remote Code Execution Vulnerability." This vulnerability is different from that described in CVE-2017-0108.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.6 | Impact: 5.9

Affected Packages4 packages

CVEListV5microsoft_corporation/windows_graphics_componentThe Windows Graphics Component in Microsoft Office 2007 SP3; 2010 SP2; and Word Viewer; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Live Meeting 2007; Silverlight 5; Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; and Windows 7 SP1, The Windows Graphics Component in Microsoft Office 2010 SP2; Windows Server 2008 R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607+1
NVDmicrosoft/windows_101511, 1607+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-2h2q-fhfv-pjvj: The Windows Graphics Component in Microsoft Office 2010 SP2; Windows Server 2008 R2 SP1; Windows 7 SP1; Windows 82022-05-13
CVEList
CVE-2017-0014: The Windows Graphics Component in Microsoft Office 2010 SP2; Windows Server 2008 R2 SP1; Windows 7 SP1; Windows 82017-03-17

📋Vendor Advisories

1
Microsoft
Windows Graphics Component Remote Code Execution Vulnerability2017-03-14

💬Community

3
Bugzilla
CVE-2016-8602 ghostscript: check for sufficient params in .sethalftone52016-10-12
Bugzilla
CVE-2013-5653 ghostscript: getenv and filenameforall ignore -dSAFER2016-09-29
Bugzilla
CVE-2016-7977 ghostscript: .libfile does not honor -dSAFER2016-09-29
CVE-2017-0014 — HIGH severity | cvebase