PT-2017-3123 · Microsoft · Office 2016 For Mac+1
Publicado
2017-10-10
·
Atualizado
2018-03-16
·
CVE-2017-11825
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Office 2016 Click-to-Run (C2R)
Microsoft Office 2016 for Mac
Description
The issue is related to how Microsoft Office handles files in memory, allowing an attacker to use a specially crafted file to perform actions in the security context of the current user. This is due to improper handling of objects in memory, leading to a buffer overflow. Exploitation of the issue may allow a remote attacker to execute actions in the system with the privileges of the current user using a specially crafted file.
Recommendations
For Microsoft Office 2016 Click-to-Run (C2R), update to a version that fixes the improper handling of objects in memory.
For Microsoft Office 2016 for Mac, update to a version that fixes the improper handling of objects in memory.
As a temporary workaround, consider avoiding the use of specially crafted files that could trigger the buffer overflow until a patch is available.
Correção
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Office 2016 Click-To-Run
Office 2016 For Mac