CVE-2017-11854
high
CVSS v3
8.8
CVSS v2
9.3
VIR risk
8.8
Description
Microsoft Word 2007 Service Pack 3, Microsoft Word 2010 Service Pack 2, Microsoft Office 2010 Service Pack 2, and Microsoft Office Compatibility Pack Service Pack 3 allow an attacker to run arbitrary code in the context of the current user by failing to properly handle objects in memory, aka "Microsoft Word Memory Corruption Vulnerability".
Predictions
Exploit likelihood
92%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: secure@microsoft.com — https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11854
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| microsoft | office | 2010 | |
| microsoft | office_compatibility_pack | - | |
| microsoft | word | 2007 | |
| microsoft | word | 2010 | |
References
- http://www.securityfocus.com/bid/101746
- http://www.securitytracker.com/id/1039795
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11854
- http://www.securityfocus.com/bid/101746
- http://www.securitytracker.com/id/1039795
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11854
CWEs
CWE-119
Verify integrity in audit chain (admin only). AS-IS.