PT-2017-2413 · Microsoft · Office+1

Pedro Gallegos

·

Publicado

2017-06-13

·

Atualizado

2019-10-03

·

CVE-2017-8506

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Outlook (affected versions not specified) Microsoft Office (affected versions not specified)
Description The issue is related to improper data handling and input validation in Microsoft Office, which can lead to remote code execution. This could allow an attacker to gain control of an affected system, enabling them to install programs, view, change, or delete data, or create new accounts with full user rights. The exploitation requires convincing a user to open a specially crafted Office document.
Recommendations For Microsoft Outlook, update to a version that properly validates input before loading dynamic link library (DLL) files. For Microsoft Office, ensure that users are cautious when opening Office documents from untrusted sources, and consider restricting user rights on the system to minimize the impact of a potential exploit. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2017-01616
CVE-2017-8506

Produtos afetados

Office
Outlook