[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247621

 
 

909

 
 

194512

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Microsoft Graphics Component Remote Code Execution - CVE-2017-8696

ID: oval:org.secpod.oval:def:42059Date: (C)2017-09-14   (M)2024-04-15
Class: VULNERABILITYFamily: windows




A remote code execution vulnerability exists due to the way Windows Uniscribe handles objects in memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. There are multiple ways an attacker could exploit this vulnerability: In a web-based attack scenario, an attacker could host a specially crafted website designed to exploit this vulnerability and then convince a user to view the website. An attacker would have no way to force users to view the attacker-controlled content. Instead, an attacker would have to convince users to take action, typically by getting them to click a link in an email or instant message that takes users to the attacker's website, or by opening an attachment sent through email. In a file-sharing attack scenario, an attacker could provide a specially crafted document file designed to exploit this vulnerability and then convince a user to open the document file.The security update addresses the vulnerability by correcting how Windows Uniscribe handles objects in memory.

Platform:
Microsoft Windows Server 2019
Microsoft Windows 7
Microsoft Windows 8
Microsoft Windows 8.1
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2012
Microsoft Windows Server 2012 R2
Microsoft Windows Vista
Microsoft Windows 10
Microsoft Windows Server 2008 R2
Microsoft Windows Server 2016
Microsoft Windows XP
Product:
Microsoft Live Meeting 2007 Add-in
Microsoft Live Meeting 2007 Console
Microsoft Lync 2010
Microsoft Lync 2010 Attendee
Microsoft Lync Basic 2013
Microsoft Office 2007
Microsoft Office 2010
Microsoft Office Web Apps 2010
Microsoft Word Viewer
Skype for Business 2016
Microsoft Skype for Business Basic 2016
Reference:
CVE-2017-8696
CVE    1
CVE-2017-8696
CPE    38
cpe:/a:microsoft:word_viewer:sp3
cpe:/o:microsoft:windows_server_2008:r2:sp1:x64
cpe:/a:microsoft:lync:2013:sp1
cpe:/o:microsoft:windows_server_2008:::x64
...

© SecPod Technologies