7.8 CVE-2017-8570

CISA Kev Catalog Used by Malware Patch Exploit
 

Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Microsoft Office Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0243.
https://nvd.nist.gov/vuln/detail/CVE-2017-8570

Categories

CWE-NVD-noinfo

References

af854a3a-2127-422b-91ae-364da2661108 Patch Exploit

secure@microsoft.com Patch Exploit


 

CPE

cpe start end
Configuration 1
cpe:2.3:a:microsoft:office:2007:sp3:*:*:*:*:*:*
cpe:2.3:a:microsoft:office:2010:sp2:*:*:*:*:*:*
cpe:2.3:a:microsoft:office:2013:sp1:*:*:*:*:*:*
cpe:2.3:a:microsoft:office:2013:sp1:*:*:rt:*:*:*
cpe:2.3:a:microsoft:office:2016:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:office:2016:*:*:*:*:*:x86:*


REMEDIATION


Patch

Url
https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2017-8570
https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2017-8570


EXPLOITS


Exploit-db.com

id description date
No known exploits

POC Github

Url
https://github.com/rxwx/CVE-2017-8570
https://github.com/SwordSheath/CVE-2017-8570
https://github.com/sasqwatch/CVE-2017-8570

Other Nist (github, ...)

Url
https://github.com/ParsingTeam/ppsx-file-generator
https://github.com/tezukanice/Office8570
https://github.com/ParsingTeam/ppsx-file-generator
https://github.com/tezukanice/Office8570


CAPEC


Common Attack Pattern Enumerations and Classifications

id description severity
No entry