CVE-2017-11762Improper Input Validation in Corporation Microsoft Graphics Component

Severity
8.8HIGHNVD
EPSS
40.7%
top 2.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 13
Latest updateMay 13

Description

The Microsoft Graphics Component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a remote code execution vulnerability in the way it handles specially crafted embedded fonts, aka "Microsoft Graphics Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-11763.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages15 packages

Patches

🔴Vulnerability Details

1
GHSA
GHSA-v5jq-x7gc-x4mv: The Microsoft Graphics Component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 82022-05-13

📋Vendor Advisories

1
Microsoft
Microsoft Graphics Remote Code Execution Vulnerability2017-10-10

🕵️Threat Intelligence

4
Qualys
October Patch Tuesday: 28 Critical Microsoft Vulnerabilities | Qualys2017-10-10
Qualys
October Patch Tuesday: 28 Critical Microsoft Vulnerabilities2017-10-10
Talos
Microsoft Patch Tuesday - October 20172017-10-10
Talos
Microsoft Patch Tuesday - October 20172017-10-10
CVE-2017-11762 — Improper Input Validation | cvebase