PT-2017-18480 · Microsoft · Windows Uniscribe+16
Published
2017-09-12
·
Updated
2017-09-21
·
CVE-2017-8695
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Windows Uniscribe in Microsoft Windows Server 2008 SP2 and R2 SP1
Windows Uniscribe in Microsoft Windows 7 SP1
Windows Uniscribe in Microsoft Windows 8.1
Windows Uniscribe in Microsoft Windows Server 2012 Gold and R2
Windows Uniscribe in Microsoft Windows RT 8.1
Windows Uniscribe in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Server 2016
Office 2007 SP3
Office 2010 SP2
Word Viewer
Office for Mac 2011 and 2016
Skype for Business 2016
Lync 2013 SP1
Lync 2010
Lync 2010 Attendee
Live Meeting 2007 Add-in and Console
Description
An information disclosure issue exists when Windows Uniscribe improperly discloses the contents of its memory. This could allow an attacker to obtain information to further compromise a user's system via a specially crafted document or an untrusted webpage.
Recommendations
For Windows Server 2008 SP2 and R2 SP1, update the system to prevent information disclosure.
For Windows 7 SP1, apply the necessary patch to fix the Windows Uniscribe issue.
For Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Server 2016, ensure the latest security updates are installed to address the vulnerability.
For Office 2007 SP3, Office 2010 SP2, Word Viewer, Office for Mac 2011 and 2016, Skype for Business 2016, Lync 2013 SP1, Lync 2010, Lync 2010 Attendee, and Live Meeting 2007 Add-in and Console, apply the recommended security updates to prevent exploitation.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Live Meeting
Lync
Office
Office 2007
Office 2010
Office For Mac
Skype For Business
Windows
Windows 10
Windows 7
Windows 8.1
Windows Rt 8.1
Windows Server 2008
Windows Server 2012
Windows Server 2016
Windows Uniscribe
Word Viewer