CVE-2017-11854
Last modified
CVE-2017-11854 is a vulnerability of currently unknown severity. Microsoft Word 2007 Service Pack 3, Microsoft Word 2010 Service Pack 2, Microsoft Office 2010 Service Pack 2, and Microsoft Office Compatibility Pack Service Pack 3 allow an attacker to run arbitrary code in the context of the current user by failing to properly handle objects in memory, aka "Microsoft Word Memory Corruption Vulnerability".. EPSS estimates a 8.36% chance of exploitation in the next 30 days.
Description
Microsoft Word 2007 Service Pack 3, Microsoft Word 2010 Service Pack 2, Microsoft Office 2010 Service Pack 2, and Microsoft Office Compatibility Pack Service Pack 3 allow an attacker to run arbitrary code in the context of the current user by failing to properly handle objects in memory, aka "Microsoft Word Memory Corruption Vulnerability".
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Microsoft | Office | 2010 | Sp2 |
| Microsoft | Office Compatibility Pack | All versions | Sp3 |
| Microsoft | Word | 2007 | Sp3 |
| Microsoft | Word | 2010 | Sp2 |
References
- http://www.securityfocus.com/bid/101746Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039795Third Party Advisory, VDB Entry
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11854Patch, Vendor Advisory
- http://www.securityfocus.com/bid/101746Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039795Third Party Advisory, VDB Entry
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11854Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-11854?
How severe is CVE-2017-11854?
How do I fix CVE-2017-11854?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-11848Internet Explorer in Microsoft Microsoft Windows 7 SP1, Wind…
- CVE-2017-11849Windows kernel in Windows 7 SP1, Windows Server 2008 SP2 and…
- CVE-2017-11850Microsoft Graphics Component in Windows 8.1 and RT 8.1, Wind…
- CVE-2017-11851The Windows kernel component on Windows 7 SP1, Windows Serve…
- CVE-2017-11852Microsoft GDI Component in Windows 7 SP1 and Windows Server …
- CVE-2017-11853Windows kernel in Windows 7 SP1, Windows Server 2008 SP2 and…
- CVE-2017-11855Internet Explorer in Microsoft Windows 7 SP1, Windows Server…
- CVE-2017-11856Internet Explorer in Microsoft Windows 7 SP1, Windows Server…
- CVE-2017-11858ChakraCore and Internet Explorer in Microsoft Windows 7 SP1,…
- CVE-2017-11861Microsoft Edge in Windows 10 1607, 1703, 1709, Windows Serve…
- CVE-2017-11862ChakraCore and Microsoft Edge in Windows 10 1709 and Windows…
- CVE-2017-11863Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 170…
Are you affected by CVE-2017-11854?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
