PT-2017-3123 · Microsoft · Office 2016 For Mac+1

Publicado

2017-10-10

·

Atualizado

2018-03-16

·

CVE-2017-11825

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Office 2016 Click-to-Run (C2R) Microsoft Office 2016 for Mac
Description The issue is related to how Microsoft Office handles files in memory, allowing an attacker to use a specially crafted file to perform actions in the security context of the current user. This is due to improper handling of objects in memory, leading to a buffer overflow. Exploitation of the issue may allow a remote attacker to execute actions in the system with the privileges of the current user using a specially crafted file.
Recommendations For Microsoft Office 2016 Click-to-Run (C2R), update to a version that fixes the improper handling of objects in memory. For Microsoft Office 2016 for Mac, update to a version that fixes the improper handling of objects in memory. As a temporary workaround, consider avoiding the use of specially crafted files that could trigger the buffer overflow until a patch is available.

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2017-02523
CVE-2017-11825

Produtos afetados

Office 2016 Click-To-Run
Office 2016 For Mac