HIGH · 7.8

CVE-2017-0108

The Windows Graphics Component in Microsoft Office 2007 SP3; 2010 SP2; and Word Viewer; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Live Meeting 2007; Silverlight 5; Windows Vista SP2; Windows ...

Vulnerability Description

The Windows Graphics Component in Microsoft Office 2007 SP3; 2010 SP2; and Word Viewer; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Live Meeting 2007; Silverlight 5; Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; and Windows 7 SP1 allows remote attackers to execute arbitrary code via a crafted web site, aka "Graphics Component Remote Code Execution Vulnerability." This vulnerability is different from that described in CVE-2017-0014.

CVSS Score

7.8

HIGH

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
MicrosoftLive Meeting2007
MicrosoftLync2010
MicrosoftOffice2007
MicrosoftSilverlight5.0
MicrosoftSkype For Business2016
MicrosoftWord Viewer-
MicrosoftWindows 7-
MicrosoftWindows Server 2008-
MicrosoftWindows Vista-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2017-0108?

CVE-2017-0108 is a vulnerability with a CVSS score of 7.8 (HIGH). The Windows Graphics Component in Microsoft Office 2007 SP3; 2010 SP2; and Word Viewer; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Live Meeting 2007; Silverlight 5; Windows Vista SP2; Windows ...

How severe is CVE-2017-0108?

CVE-2017-0108 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2017-0108?

Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Live Meeting, Microsoft Lync, Microsoft Office, Microsoft Silverlight, Microsoft Skype For Business.