CVE-2017-0108CriticalCVSS 8.8

Windows Graphics Component Remote Code Execution Vulnerability

Published
March 14, 2017
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

A remote code execution vulnerability exists due to the way the Windows Graphics Component handles objects in memory. An attacker who successfully exploited the vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. There are multiple ways an attacker could exploit the vulnerability: In a web-based attack scenario, an attacker could host a specially crafted website that is designed to exploit this vulnerability and then convince a user to view the website. An attacker would have no way to force users to view the attacker-controlled content. Instead, an attacker would have to convince users to take action, typically by getting them to click a link in an email message or in an Instant Messenger message that takes users to the attacker's website, or by opening an attachment sent through email. In a file sharing attack scenario, an attacker could provide a specially crafted document file that is designed to exploit the vulnerability, and then convince a user to open the document file. Note that for affected Microsoft Office products, the Preview Pane is an attack vector. The security update addresses the vulnerability by correcting how the Windows Graphics Component handles objects in the memory.

🎯 Affected products32

  • Microsoft Lync 2010 (32-bit)
  • Microsoft Lync 2010 (64-bit)
  • Microsoft Lync 2010 Attendee (admin level install)
  • Microsoft Lync 2010 Attendee (user level install)
  • Microsoft Lync 2013 Service Pack 1 (32-bit)
  • Microsoft Lync 2013 Service Pack 1 (64-bit)
  • Microsoft Lync Basic 2013 Service Pack 1 (32-bit)
  • Microsoft Lync Basic 2013 Service Pack 1 (64-bit)
  • Microsoft Office 2007 Service Pack 3
  • Microsoft Office 2010 Service Pack 2 (32-bit editions)
  • Microsoft Office 2010 Service Pack 2 (64-bit editions)
  • Microsoft Office Word Viewer
  • Microsoft Silverlight 5 Developer Runtime when installed on Microsoft Windows (32-bit)
  • Microsoft Silverlight 5 Developer Runtime when installed on Microsoft Windows (x64-based)
  • Microsoft Silverlight 5 when installed on Microsoft Windows (32-bit)
  • Microsoft Silverlight 5 when installed on Microsoft Windows (x64-based)
  • Skype for Business 2016 (32-bit)
  • Skype for Business 2016 (64-bit)
  • Skype for Business 2016 Basic (32-bit)
  • Skype for Business 2016 Basic (64-bit)
  • Windows 7 for 32-bit Systems Service Pack 1
  • Windows 7 for x64-based Systems Service Pack 1
  • Windows Server 2008 R2 for Itanium-Based Systems Service Pack 1
  • Windows Server 2008 R2 for x64-based Systems Service Pack 1
  • Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
  • Windows Server 2008 for 32-bit Systems Service Pack 2
  • Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
  • Windows Server 2008 for Itanium-Based Systems Service Pack 2
  • Windows Server 2008 for x64-based Systems Service Pack 2
  • Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)
  • +2 more not shown

✅ Remediation

KB3127958 (Security Update) KB3178693 (Security Update) KB3178653 (Security Update) KB4012215 (Monthly Rollup) KB4012212 (Security Only) KB4012583 (Security Update) KB4013867 (Security Update) KB4010299 (Security Update) KB4010301 (Security Update) KB4010300 (Security Update) KB3172539 (Security Update) KB3178656 (Security Update) KB3141535 (Security Update) KB3127945 (Security Update)

🔗 References (33)