Vulnerability Description
A remote code execution vulnerability exists in Microsoft PowerPoint 2007 Service Pack 3, Microsoft PowerPoint 2010 Service Pack 2, Microsoft PowerPoint 2013 Service Pack 1, Microsoft PowerPoint 2013 RT Service Pack 1, Microsoft PowerPoint 2016, Microsoft PowerPoint Viewer 2007, Microsoft SharePoint Server 2013 Service Pack 1, Microsoft SharePoint Enterprise Server 2016, Microsoft Office Web Apps 2010 Service Pack 2, and Microsoft Office Compatibility Pack Service Pack 3 when they fail to properly handle objects in memory, aka "PowerPoint Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-8743.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Office Compatibility Pack | - |
| Microsoft | Office Web Apps | 2010 |
| Microsoft | Office Web Apps Server | 2013 |
| Microsoft | Powerpoint | 2007 |
| Microsoft | Powerpoint Viewer | 2010 |
| Microsoft | Sharepoint Enterprise Server | 2016 |
| Microsoft | Sharepoint Server | 2016 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/100741Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1039323Third Party AdvisoryVDB Entry
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8742PatchVendor Advisory
- http://www.securityfocus.com/bid/100741Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1039323Third Party AdvisoryVDB Entry
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8742PatchVendor Advisory
FAQ
What is CVE-2017-8742?
CVE-2017-8742 is a vulnerability with a CVSS score of 7.8 (HIGH). A remote code execution vulnerability exists in Microsoft PowerPoint 2007 Service Pack 3, Microsoft PowerPoint 2010 Service Pack 2, Microsoft PowerPoint 2013 Service Pack 1, Microsoft PowerPoint 2013 ...
How severe is CVE-2017-8742?
CVE-2017-8742 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-8742?
Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Office Compatibility Pack, Microsoft Office Web Apps, Microsoft Office Web Apps Server, Microsoft Powerpoint, Microsoft Powerpoint Viewer.