CVE-2017-8682

HIGH

Description

Windows graphics on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, Windows Server 2016, Microsoft Office Word Viewer, Microsoft Office 2007 Service Pack 3 , and Microsoft Office 2010 Service Pack 2 allows an attacker to execute remote code by the way it handles embedded fonts, aka "Win32k Graphics Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-8683.

References

http://www.securityfocus.com/bid/100772

http://www.securitytracker.com/id/1039352

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8682

https://www.exploit-db.com/exploits/42744/

Details

Source: MITRE

Published: 2017-09-13

Updated: 2019-05-10

Type: CWE-20

Risk Information

CVSS v2.0

Base Score: 9.3

Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 8.6

Severity: HIGH

CVSS v3.0

Base Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 2.8

Severity: HIGH

Tenable Plugins

View all (10 total)

IDNameProductFamilySeverity
104385KB4038781: Windows 10 September 2017 Cumulative UpdateNessusWindows : Microsoft Bulletins
high
103140Windows 2008 September 2017 Multiple Security UpdatesNessusWindows : Microsoft Bulletins
high
103135Security Updates for Microsoft Office Viewers (September 2017)NessusWindows : Microsoft Bulletins
high
103133Security Updates for Microsoft Office Products (September 2017)NessusWindows : Microsoft Bulletins
high
103132Windows Server 2012 September 2017 Security UpdatesNessusWindows : Microsoft Bulletins
high
103131Windows 8.1 and Windows Server 2012 R2 September 2017 Security UpdatesNessusWindows : Microsoft Bulletins
high
103130KB4038788: Windows 10 Version 1703 September 2017 Cumulative UpdateNessusWindows : Microsoft Bulletins
high
103129KB4038783: Windows 10 Version 1511 September 2017 Cumulative UpdateNessusWindows : Microsoft Bulletins
high
103128KB4038782: Windows 10 Version 1607 and Windows Server 2016 September 2017 Cumulative UpdateNessusWindows : Microsoft Bulletins
high
103127Windows 7 and Windows Server 2008 R2 September 2017 Security UpdatesNessusWindows : Microsoft Bulletins
high