CVE-2017-11877 Information

Description

Microsoft Excel 2007 Service Pack 3 Microsoft Excel 2010 Service Pack 2 Microsoft Excel 2013 Service Pack 1 Microsoft Excel 2013 RT Service Pack 1 Microsoft Excel 2016 Microsoft Office Compatibility Pack Service Pack 3 Microsoft Excel Viewer 2007 Service Pack 3 and Microsoft Excel 2016 for Mac allow a security feature bypass by not enforcing macro settings on an Excel document aka \Microsoft Excel Security Feature Bypass Vulnerability.

CVSS Vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Reference

http://www.securityfocus.com/bid/101747 http://www.securitytracker.com/id/1039783 https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11877

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

REQUIRED

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

HIGH

Base Score

NONE

Base Severity

5.5

Share on: