Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.811697
Category:Windows : Microsoft Bulletins
Title:Microsoft Office Word Viewer Multiple Vulnerabilities (KB4011134)
Summary:This host is missing a critical security; update according to Microsoft KB4011134
Description:Summary:
This host is missing a critical security
update according to Microsoft KB4011134

Vulnerability Insight:
Multiple flaws exist due to:

- An error in the way Windows Graphics Device Interface (GDI) handles objects
in memory,

- An error in the Windows font library which improperly handles specially
crafted embedded fonts.

- An error when Windows Uniscribe improperly discloses the contents of its
memory.

Vulnerability Impact:
Successful exploitation will allow an attacker
to retrieve information from a targeted system. By itself, the information
disclosure does not allow arbitrary code execution. However, it could allow
arbitrary code to be run if the attacker uses it in combination with another
vulnerability.

Affected Software/OS:
Microsoft Office Word Viewer.

Solution:
The vendor has released updates. Please see the references for more information.

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2017-8676
BugTraq ID: 100755
http://www.securityfocus.com/bid/100755
http://www.securitytracker.com/id/1039333
Common Vulnerability Exposure (CVE) ID: CVE-2017-8682
BugTraq ID: 100772
http://www.securityfocus.com/bid/100772
https://www.exploit-db.com/exploits/42744/
http://www.securitytracker.com/id/1039352
Common Vulnerability Exposure (CVE) ID: CVE-2017-8695
BugTraq ID: 100773
http://www.securityfocus.com/bid/100773
http://www.securitytracker.com/id/1039344
CopyrightCopyright (C) 2017 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.