PT-2017-2926 · Microsoft · Office Online Server+4
Publicado
2017-09-12
·
Atualizado
2017-09-21
·
CVE-2017-8743
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft PowerPoint 2016
Microsoft SharePoint Enterprise Server 2016
Office Online Server (affected versions not specified)
Description
A remote code execution issue exists when the software fails to properly handle objects in memory. This could allow an attacker to run arbitrary code in the context of the current user. If the user has administrative rights, the attacker could take control of the system, install programs, view, change, or delete data, or create new accounts with full user rights. The exploitation requires a user to open a specially crafted file with an affected version of the software.
Recommendations
For Microsoft PowerPoint 2016, consider avoiding the use of specially crafted ppt files until a patch is available.
For Microsoft SharePoint Enterprise Server 2016, restrict access to potentially vulnerable areas of the server to minimize the risk of exploitation.
For Office Online Server, as a temporary workaround, consider disabling the handling of objects in memory until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Powerpoint 2016
Sharepoint Enterprise Server 2016
Office Online Server
Office Powerpoint
Sharepoint Server