CVE-2017-8742
Summary
| CVE | CVE-2017-8742 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-09-13 01:29:00 UTC |
| Updated | 2017-09-29 18:58:00 UTC |
| Description | A remote code execution vulnerability exists in Microsoft PowerPoint 2007 Service Pack 3, Microsoft PowerPoint 2010 Service Pack 2, Microsoft PowerPoint 2013 Service Pack 1, Microsoft PowerPoint 2013 RT Service Pack 1, Microsoft PowerPoint 2016, Microsoft PowerPoint Viewer 2007, Microsoft SharePoint Server 2013 Service Pack 1, Microsoft SharePoint Enterprise Server 2016, Microsoft Office Web Apps 2010 Service Pack 2, and Microsoft Office Compatibility Pack Service Pack 3 when they fail to properly handle objects in memory, aka "PowerPoint Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-8743. |
Risk And Classification
Problem Types: CWE-119
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Office Compatibility Pack | - | sp3 | All | All |
| Application | Microsoft | Office Compatibility Pack | - | sp3 | All | All |
| Application | Microsoft | Office Web Apps | 2010 | sp2 | All | All |
| Application | Microsoft | Office Web Apps | 2010 | sp2 | All | All |
| Application | Microsoft | Office Web Apps Server | 2013 | sp1 | All | All |
| Application | Microsoft | Office Web Apps Server | 2013 | sp1 | All | All |
| Application | Microsoft | Powerpoint | 2007 | sp3 | All | All |
| Application | Microsoft | Powerpoint | 2010 | sp2 | All | All |
| Application | Microsoft | Powerpoint | 2013 | sp1 | All | All |
| Application | Microsoft | Powerpoint | 2013 | sp1 | All | All |
| Application | Microsoft | Powerpoint | 2016 | All | All | All |
| Application | Microsoft | Powerpoint | 2007 | sp3 | All | All |
| Application | Microsoft | Powerpoint | 2010 | sp2 | All | All |
| Application | Microsoft | Powerpoint | 2013 | sp1 | All | All |
| Application | Microsoft | Powerpoint | 2013 | sp1 | All | All |
| Application | Microsoft | Powerpoint | 2016 | All | All | All |
| Application | Microsoft | Powerpoint Viewer | 2010 | All | All | All |
| Application | Microsoft | Powerpoint Viewer | 2010 | All | All | All |
| Application | Microsoft | Sharepoint Enterprise Server | 2016 | All | All | All |
| Application | Microsoft | Sharepoint Enterprise Server | 2016 | All | All | All |
| Application | Microsoft | Sharepoint Server | 2016 | All | All | All |
| Application | Microsoft | Sharepoint Server | 2016 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Microsoft PowerPoint CVE-2017-8742 Remote Code Execution Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Microsoft PowerPoint File Processing Flaws Let Remote Users Execute Arbitrary Code - SecurityTracker | SECTRACK | www.securitytracker.com | Third Party Advisory, VDB Entry |
| {{windowTitle}} | CONFIRM | portal.msrc.microsoft.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.