CVE-2017-11825

CWE-119Buffer Overflow4 documents4 sources
Severity
7.8HIGH
EPSS
32.4%
top 3.15%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 13
Latest updateMay 14

Description

Microsoft Office 2016 Click-to-Run (C2R) and Microsoft Office 2016 for Mac allow an attacker to use a specially crafted file to perform actions in the security context of the current user, due to how Microsoft Office handles files in memory, aka "Microsoft Office Remote Code Execution Vulnerability".

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-f6q6-xhg5-qpp7: Microsoft Office 2016 Click-to-Run (C2R) and Microsoft Office 2016 for Mac allow an attacker to use a specially crafted file to perform actions in the2022-05-14
CVEList
CVE-2017-11825: Microsoft Office 2016 Click-to-Run (C2R) and Microsoft Office 2016 for Mac allow an attacker to use a specially crafted file to perform actions in the2017-10-13

📋Vendor Advisories

1
Microsoft
Microsoft Office Remote Code Execution Vulnerability2017-10-10
CVE-2017-11825 (HIGH CVSS 7.8) | Microsoft Office 2016 Click-to-Run | cvebase.io