Vulnerability   
Search   
    Search 219043 CVE descriptions
and 99761 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.810688
Category:Windows : Microsoft Bulletins
Title:Microsoft Office Suite Remote Code Execution Vulnerability (KB3178710)
Summary:This host is missing a critical update for; Microsoft Office Suite according to Microsoft KB33178710.
Description:Summary:
This host is missing a critical update for
Microsoft Office Suite according to Microsoft KB33178710.

Vulnerability Insight:
The flaw exists due to error in the way
Microsoft Office and WordPad parse specially crafted files.

Vulnerability Impact:
Successful exploitation will allow remote
attackers to run arbitrary code in the context of the current user on an
affected system.

Affected Software/OS:
Microsoft Office 2013 Service Pack 1.

Solution:
The vendor has released updates. Please see the references for more information.

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Cross-Ref: BugTraq ID: 97498
Common Vulnerability Exposure (CVE) ID: CVE-2017-0199
http://www.securityfocus.com/bid/97498
https://www.exploit-db.com/exploits/41894/
https://www.exploit-db.com/exploits/41934/
https://www.exploit-db.com/exploits/42995/
http://rewtin.blogspot.nl/2017/04/cve-2017-0199-practical-exploitation-poc.html
https://blog.nviso.be/2017/04/12/analysis-of-a-cve-2017-0199-malicious-rtf-document/
https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02
https://www.fireeye.com/blog/threat-research/2017/04/cve-2017-0199_useda.html
https://www.mdsec.co.uk/2017/04/exploiting-cve-2017-0199-hta-handler-vulnerability/
http://www.securitytracker.com/id/1038224
CopyrightCopyright (C) 2017 Greenbone Networks GmbH

This is only one of 99761 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2024 E-Soft Inc. All rights reserved.