PT-2017-2153 · Microsoft · Office

Genwei Jiang

+1

·

Published

2017-05-09

·

Updated

2025-02-11

·

CVE-2017-0261

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Office versions 2010 through 2016
Description The issue exists due to insufficient input validation in Microsoft Office, allowing a remote attacker to execute arbitrary code. Exploitation can occur when a user opens a specially crafted file, such as an EPS file with a malformed graphic image, or inserts a malformed graphic image into an Office file. Such files can also be attached to emails. Successful exploitation can grant the attacker control over the system.
Recommendations For Microsoft Office versions 2010 through 2016, apply the official fix to resolve the issue. As a temporary workaround, consider avoiding the use of specially crafted EPS files and restricting the insertion of graphic images from untrusted sources into Office files until a patch is applied.

Exploit

Fix

RCE

Use After Free

Weakness Enumeration

Related Identifiers

BDU:2017-01346
CVE-2017-0261

Affected Products

Office