PT-2017-2930 · Microsoft · Windows Server 2016+6
Published
2017-09-12
·
Updated
2017-09-21
·
CVE-2017-8737
CVSS v2.0
7.6
High
| Vector | AV:N/AC:H/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows PDF Library versions 8.1 through 10, Windows Server 2012 and 2016
Description
The issue allows an attacker to execute arbitrary code in the context of the current user due to the way that Windows PDF Library handles objects in memory. This can be exploited by visiting a specially prepared website using Microsoft Edge in Windows 10, or by opening a specially created PDF document in other affected systems. If the current user is logged on with administrative user rights, an attacker could take control of an affected system, enabling them to install programs, view, change, or delete data, or create new accounts with full user rights.
Recommendations
For Windows 8.1, update to a newer version to mitigate the risk.
For Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016, update to a newer version to mitigate the risk.
As a temporary workaround, consider disabling the Microsoft Edge browser or restricting access to PDF files until a patch is available.
Avoid opening specially created PDF documents from untrusted sources until the issue is resolved.
Fix
RCE
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Edge
Windows
Windows 10
Windows 8.1
Windows Pdf Library
Windows Server 2012
Windows Server 2016