CVE-2017-8571High
Microsoft Office Security Feature Bypass Vulnerability
🔗 CVE IDs covered (1)
📋 Description
A security feature bypass vulnerability exists when Microsoft Office improperly handles input. An attacker who successfully exploited the vulnerability could execute arbitrary commands. In a file-sharing attack scenario, an attacker could provide a specially crafted document file designed to exploit the vulnerability, and then convince a user to open the document file and interact with the document by clicking a specific cell. The update addresses the vulnerability by correcting how Microsoft Office handles input.
🎯 Affected products14
- Microsoft Office 2010 Click-to-Run (C2R) for 32-bit editions
- Microsoft Office 2010 Click-to-Run (C2R) for 64-bit editions
- Microsoft Office 2013 Click-to-Run (C2R) for 32-bit editions
- Microsoft Office 2013 Click-to-Run (C2R) for 64-bit editions
- Microsoft Office 2016 Click-to-Run (C2R) for 32-bit editions
- Microsoft Office 2016 Click-to-Run (C2R) for 64-bit editions
- Microsoft Outlook 2007 Service Pack 3
- Microsoft Outlook 2010 Service Pack 2 (32-bit editions)
- Microsoft Outlook 2010 Service Pack 2 (64-bit editions)
- Microsoft Outlook 2013 RT Service Pack 1
- Microsoft Outlook 2013 Service Pack 1 (32-bit editions)
- Microsoft Outlook 2013 Service Pack 1 (64-bit editions)
- Microsoft Outlook 2016 (32-bit edition)
- Microsoft Outlook 2016 (64-bit edition)
✅ Remediation
KBClick to Run (Security Update) KB3213643 (Security Update) KB2956078 (Security Update) KB4011078 (Security Update) KB4011052 (Security Update)
🔗 References (8)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2017-8571
- patchhttps://www.microsoft.com/downloads/details.aspx?familyid=d2ae8131-a475-4c06-8508-bae1fc26a1e6
- patchhttps://www.microsoft.com/downloads/details.aspx?familyid=78a9ba80-4bed-4f59-bdc8-1048e5a85cd9
- patchhttps://www.microsoft.com/downloads/details.aspx?familyid=23cbebff-46df-43c0-af9d-887636e6c348
- patchhttps://www.microsoft.com/downloads/details.aspx?familyid=bda6d459-1562-4cf2-9356-08e53a8c9818
- patchhttps://www.microsoft.com/downloads/details.aspx?familyid=4612ec7f-4a93-4db9-8e2b-275a2086f07d
- patchhttps://www.microsoft.com/downloads/details.aspx?familyid=5780cd73-4f3b-4a4a-9f1e-e7f246ec8a07
- patchhttps://www.microsoft.com/downloads/details.aspx?familyid=0fc588ad-e887-4dd4-8cc9-fa86546a88ee