PT-2017-2926 · Microsoft · Office Online Server+4

Publicado

2017-09-12

·

Atualizado

2017-09-21

·

CVE-2017-8743

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft PowerPoint 2016 Microsoft SharePoint Enterprise Server 2016 Office Online Server (affected versions not specified)
Description A remote code execution issue exists when the software fails to properly handle objects in memory. This could allow an attacker to run arbitrary code in the context of the current user. If the user has administrative rights, the attacker could take control of the system, install programs, view, change, or delete data, or create new accounts with full user rights. The exploitation requires a user to open a specially crafted file with an affected version of the software.
Recommendations For Microsoft PowerPoint 2016, consider avoiding the use of specially crafted ppt files until a patch is available. For Microsoft SharePoint Enterprise Server 2016, restrict access to potentially vulnerable areas of the server to minimize the risk of exploitation. For Office Online Server, as a temporary workaround, consider disabling the handling of objects in memory until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2017-02251
CVE-2017-8743
ZDI-17-732

Produtos afetados

Powerpoint 2016
Sharepoint Enterprise Server 2016
Office Online Server
Office Powerpoint
Sharepoint Server