Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2017-0108

CWE-119Buffer Overflow6 documents6 sources
Severity
7.8HIGH
EPSS
36.7%
top 2.86%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedMar 17
Latest updateMay 17

Description

The Windows Graphics Component in Microsoft Office 2007 SP3; 2010 SP2; and Word Viewer; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Live Meeting 2007; Silverlight 5; Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; and Windows 7 SP1 allows remote attackers to execute arbitrary code via a crafted web site, aka "Graphics Component Remote Code Execution Vulnerability." This vulnerability is different from that described in CVE-2017-0014.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages7 packages

CVEListV5microsoft_corporation/windows_graphics_componentThe Windows Graphics Component in Microsoft Office 2007 SP3; 2010 SP2; and Word Viewer; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Live Meeting 2007; Silverlight 5; Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; and Windows 7 SP1
NVDmicrosoft/lync2010, 2013+1
NVDmicrosoft/skype2016

Patches

🔴Vulnerability Details

3
GHSA
GHSA-qp4j-h89h-v85j: The Windows Graphics Component in Microsoft Office 2007 SP3; 2010 SP2; and Word Viewer; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Live Meetin2022-05-17
Project0
Notes on Windows Uniscribe Fuzzing - Project Zero2017-04-01
CVEList
CVE-2017-0108: The Windows Graphics Component in Microsoft Office 2007 SP3; 2010 SP2; and Word Viewer; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Live Meetin2017-03-17

💥Exploits & PoCs

1
Exploit-DB
Microsoft Windows - 'USP10!otlList::insertAt' Uniscribe Font Processing Heap Buffer Overflow (MS17-011)2017-03-20

📋Vendor Advisories

1
Microsoft
Windows Graphics Component Remote Code Execution Vulnerability2017-03-14
CVE-2017-0108 (HIGH CVSS 7.8) | The Windows Graphics Component in M | cvebase.io