CVE-2017-11825
high · 7.8Microsoft Office 2016 Click-to-Run (C2R) and Microsoft Office 2016 for Mac allow an attacker to use a specially crafted file to perform actions in the security context of the current user, due to how Microsoft Office handles files in memory, aka "Microsoft Office Remote Code Execution Vulnerability".
7.8
CVSS
22.9%
EPSS (exploit prob.)
98th
EPSS percentile
2017-10-13
Published
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weaknesses
CWE-119
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | office | 2016 |
| microsoft | office_for_mac | 2016 |
Check a specific version with /api/v1/cve/match.
References
- http://www.securityfocus.com/bid/101124
- http://www.securitytracker.com/id/1039539
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11825
- http://www.securityfocus.com/bid/101124
- http://www.securitytracker.com/id/1039539
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11825
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2017-11825