CVE-2017-0292Corporation Windows PDF vulnerability

5 documents5 sources
Severity
7.8HIGHNVD
EPSS
28.4%
top 3.47%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 15
Latest updateMay 13

Description

Windows PDF in Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows remote code execution if a user opens a specially crafted PDF file, aka "Windows PDF Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0291.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages4 packages

NVDmicrosoft/windows_101511, 1607, 1703+2
CVEListV5microsoft_corporation/windows_pdfWindows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016
NVDmicrosoft/word2013, 2016+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-hvhc-4cj4-9j3j: Windows PDF in Windows 82022-05-13
CVEList
CVE-2017-0292: Windows PDF in Windows 82017-06-15

📋Vendor Advisories

1
Microsoft
Windows PDF Remote Code Execution Vulnerability2017-06-13
CVE-2017-0292 — Corporation Windows PDF vulnerability | cvebase