PT-2017-2413 · Microsoft · Office+1
Pedro Gallegos
·
Published
2017-06-13
·
Updated
2019-10-03
·
CVE-2017-8506
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Outlook (affected versions not specified)
Microsoft Office (affected versions not specified)
Description
The issue is related to improper data handling and input validation in Microsoft Office, which can lead to remote code execution. This could allow an attacker to gain control of an affected system, enabling them to install programs, view, change, or delete data, or create new accounts with full user rights. The exploitation requires convincing a user to open a specially crafted Office document.
Recommendations
For Microsoft Outlook, update to a version that properly validates input before loading dynamic link library (DLL) files.
For Microsoft Office, ensure that users are cautious when opening Office documents from untrusted sources, and consider restricting user rights on the system to minimize the impact of a potential exploit.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Office
Outlook