CVE-2017-0108
The Windows Graphics Component in Microsoft Office 2007 SP3; 2010 SP2; and Word Viewer; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Live Meeting 2007; Silverlight 5; Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; and Windows 7 SP1 allows remote attackers to execute arbitrary code via a crafted web site, aka "Graphics Component Remote Code Execution Vulnerability." This vulnerability is different from that described in CVE-2017-0014.
- Affected products
- Live Meeting 2007, Lync 2010, Lync 2013, Office 2007, Office 2010, Office, Silverlight 5, Skype For Business 2016
- Microsoft Live Meeting
- = 2007
- Microsoft Lync
- = 2010, 2013
- Microsoft Office
- = 2007, 2010
- Microsoft Silverlight
- = 5.0
- Microsoft Skype For Business
- = 2016
- Microsoft Word Viewer
- All versions
- Fix
- Available
- CVSS 2.0
- 9.3 HIGH
- CVSS 3.1
- 7.8 HIGH
- EPSS
- 59.4% (99th percentile)
- Weakness
- CWE-119
- NVD status
- Modified
- Published
- 2017-03-17
CVE-2017-0108 at NVD
3 known exploits for CVE-2017-0108
Proof-of-concept code and exploit modules indexed by Sploitus