CVE-2017-11825 Information
Feb 14, 2021
cve
Description
Microsoft Office 2016 Click-to-Run (C2R) and Microsoft Office 2016 for Mac allow an attacker to use a specially crafted file to perform actions in the security context of the current user due to how Microsoft Office handles files in memory aka \Microsoft Office Remote Code Execution Vulnerability.
CVSS Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Reference
http://www.securityfocus.com/bid/101124 http://www.securitytracker.com/id/1039539 https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11825
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
7.8
Share on: