cbcvebase.
CVE-2017-0108
published 2017-03-17

CVE-2017-0108: The Windows Graphics Component in Microsoft Office 2007 SP3; 2010 SP2; and Word Viewer; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Live Meeting 2007…

PriorityP267high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EXPLOIT
EPSS
50.47%
98.8th percentile
The Windows Graphics Component in Microsoft Office 2007 SP3; 2010 SP2; and Word Viewer; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Live Meeting 2007; Silverlight 5; Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; and Windows 7 SP1 allows remote attackers to execute arbitrary code via a crafted web site, aka "Graphics Component Remote Code Execution Vulnerability." This vulnerability is different from that described in CVE-2017-0014.

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftlive_meeting
microsoftlync
microsoftlync
microsoftoffice
microsoftoffice
microsoftsilverlight
microsoftskype_for_business
microsoftwindows_10
microsoftwindows_10
microsoftwindows_server_2008
microsoftwindows_server_2012
microsoft_corporationwindows_graphics_component
msrcmicrosoft_lync_2010
msrcmicrosoft_lync_2010_attendee
msrcmicrosoft_lync_2013_service_pack_1
msrcmicrosoft_lync_basic_2013_service_pack_1
msrcmicrosoft_office_2007_service_pack_3
msrcmicrosoft_office_2010_service_pack_2
msrcmicrosoft_office_word_viewer
msrcmicrosoft_silverlight_5_developer_runtime_when_installed
msrcmicrosoft_silverlight_5_when_installed
msrcskype
msrcwindows_7
msrcwindows_server_2008
msrcwindows_server_2008_r2

Detection & IOCsextracted from sources · hover to see the quote

urlhttps://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/41647.zip
urlhttps://bugs.chromium.org/p/project-zero/issues/detail?id=1022
  • Crash occurs in USP10!otlList::insertAt via memmove() when processing a specially crafted/corrupted font file through the Windows Uniscribe library (USP10.dll); monitor for heap buffer overflow in this call path.
  • The exploit call stack passes through ScriptStringAnalyse -> LpkStringAnalyse -> LpkCharsetDraw -> LpkDrawTextEx -> DrawTextExW/DrawTextW; monitor for anomalous font rendering via these USER32/LPK APIs triggered by Office documents or web content.
  • Attack vector includes Office document Preview Pane; flag suspicious font-embedded Office documents (Word, Excel, Visio) opened or previewed without user interaction.
  • Exploitation path also includes web-based delivery; monitor for users being directed to attacker-controlled websites via links in email or Instant Messenger messages.
  • Enable PageHeap on test systems to reliably reproduce the heap buffer overflow crash in USP10!otlList::insertAt for detection/triage purposes.
  • The vulnerability is triggered during Hebrew glyph shaping; look for USP10!HebrewEngineGetGlyphs in crash telemetry or WER reports as an indicator of exploitation attempts.
  • ·The KB3127958 (Ogl.dll) update for Office 2010 is NOT applicable on Windows Vista and later; the vulnerable code is not present in that configuration.
  • ·Lync 2013 (Skype for Business) requires prerequisite updates 2965218 and 3039779 before the CVE-2017-0108 patch can be applied.
  • ·CVE-2017-0108 is a distinct vulnerability from CVE-2017-0014, though both affect the Windows Graphics Component and share the same bulletin.

CVSS provenance

nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_msrc8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.