A remote code execution vulnerability exists in Microsoft Excel 2010 Service Pack 2, Microsoft Excel 2013 Service Pack 1, Microsoft Excel 2013 RT Service Pack 1, Microsoft Excel 2016, Microsoft Office Web Apps 2013, Microsoft Excel for Mac 2011, Microsoft Excel 2016 for Mac, and Microsoft Office Compatibility Pack Service Pack 3, when they fail to properly handle objects in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8630, CVE-2017-8631, and CVE-2017-8744.
CVSS Details
- CVSS 3.0 Base Score: 7.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Microsoft Office | — | Download and install Microsoft KB4011050 | Jun 20, 2023 | Sep 13, 2017 |
| Msft | — | Security Update for Microsoft Excel 2013 (KB4011108) 64-Bit EditionSecurity Update for Microsoft Excel 2010 (KB4011061) 64-Bit EditionSecurity Update for Microsoft Excel 2010 (KB4011061) 32-Bit EditionSecurity Update for Microsoft Office Compatibility Pack Service Pack 3 (KB4011064)Security Update for Microsoft Excel 2013 (KB4011108) 32-Bit Edition | Sep 12, 2017 | Sep 12, 2017 |
| Office For Mac | — | Upgrade to Office for Mac version 15.38.0Upgrade to Office for Mac version 14.7.7 | Sep 12, 2017 | Sep 12, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub