CVE-2017-0006

high
Published 2017-03-17 ยท Modified 2026-05-13
CVSS v3
7.8
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
7.8

Description

Microsoft Excel 2007 SP3, Office Compatibility Pack SP3, Excel Viewer, and Excel Services on SharePoint Server 2007 SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability." This vulnerability is different from those described in CVE-2017-0019, CVE-2017-0020, CVE-2017-0030, CVE-2017-0031, CVE-2017-0052, and CVE-2017-0053.

Predictions

Exploit likelihood
75%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Microsoft Security Response Center ยท View original โ†— ยท proprietary-no-redistribution
Full prose not cached โ€” VIR stores only structured fields (affected/fixed versions, references) for this source. Click "View original" above for the vendor's full advisory.

Affected

VendorProductVersion
microsoftMicrosoft Word for Mac 2011
microsoftMicrosoft Excel for Mac 2011
microsoftWindows 7 for 32-bit Systems Service Pack 1
microsoftWindows 7 for x64-based Systems Service Pack 1
microsoftWindows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
microsoftWindows Server 2008 R2 for Itanium-Based Systems Service Pack 1
microsoftWindows Server 2008 R2 for x64-based Systems Service Pack 1
microsoftMicrosoft Lync 2010 (32-bit)
microsoftMicrosoft Silverlight 5 when installed on Microsoft Windows (x64-based)
microsoftMicrosoft Lync for Mac 2011
microsoftMicrosoft Office 2007 Service Pack 3
microsoftMicrosoft Excel 2007 Service Pack 3
microsoftMicrosoft Word 2007 Service Pack 3
microsoftMicrosoft Lync 2010 Attendee (admin level install)
microsoftMicrosoft Excel Viewer 2007 Service Pack 3
microsoftWindows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
microsoftMicrosoft Live Meeting 2007 Console
microsoftMicrosoft Lync 2010 Attendee (user level install)
microsoftMicrosoft Lync 2010 (64-bit)
microsoftInternet Explorer 9 on Windows Vista Service Pack 2
microsoftInternet Explorer 9 on Windows Server 2008 for 32-bit Systems Service Pack 2
microsoftInternet Explorer 9 on Windows Vista x64 Edition Service Pack 2
microsoftInternet Explorer 9 on Windows Server 2008 for x64-based Systems Service Pack 2
microsoftWindows Server 2012
microsoftWindows Server 2012 (Server Core installation)
microsoftAdobe Flash Player on Windows Server 2012
microsoftAdobe Flash Player on Windows 8.1 for 32-bit systems
microsoftAdobe Flash Player on Windows 8.1 for x64-based systems
microsoftAdobe Flash Player on Windows Server 2012 R2
microsoftAdobe Flash Player on Windows RT 8.1

Application impact

VendorProductVersionsFixed
windows microsoftexcel2007
windows microsoftexcel_viewer
windows microsoftoffice_compatibility_pack
windows microsoftsharepoint_server2007

References

CWEs

CWE-119

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.