Windows graphics on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, Windows Server 2016, Microsoft Office Word Viewer, Microsoft Office 2007 Service Pack 3 , and Microsoft Office 2010 Service Pack 2 allows an attacker to execute remote code by the way it handles embedded fonts, aka "Win32k Graphics Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-8683.
CVSS Details
- CVSS 3.0 Base Score: 8.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Msft | — | 2017-09 Cumulative Update for Microsoft Windows Server 2016, version 1607 (KB4038782)2017-09 Security Only Quality Update for Windows Embedded Standard 7 for x86-based Systems (KB4038779)Security Update for WES09 and POSReady 2009 (KB4039384)Security Update for Word Viewer (KB4011134)Security Update for Microsoft Office 2007 suites (KB3213641)Security Update for Windows Server 2008 (KB4039384)2017-09 Cumulative Update for Microsoft Windows Server 2012 R2 (KB4038793)2017-09 Cumulative Update for Microsoft Windows 10, version 1607 (KB4038782)2017-09 Security Only Quality Update for Windows Server 2008 R2 for x64-based Systems (KB4038779)2017-09 Security Only Quality Update for Windows 8.1 for x64-based Systems (KB4038793)2017-09 Cumulative Update for Microsoft Windows 10, version 1703 (KB4038788)2017-09 Cumulative Update for Microsoft Windows Server 2012 (KB4038786)2017-09 Security Only Quality Update for Windows Embedded 8 Standard for x64-based Systems (KB4038786)2017-09 Security Only Quality Update for Windows Embedded Standard 7 for x64-based Systems (KB4038779)Security Update for Microsoft Office 2010 (KB3213638) 32-Bit EditionSecurity Update for Microsoft Office 2010 (KB3213638) 64-Bit Edition2017-09 Cumulative Update for Microsoft Windows 10, version 1511 (KB4038783)2017-09 Cumulative Update for Microsoft Windows 10, version 1507 (KB4038781)2017-09 Security Only Quality Update for Windows Server 2008 R2 for Itanium-based Systems (KB4038779)Security Update for Windows Server 2008 for Itanium-based Systems (KB4039384)Security Update for Windows Server 2008 for x64-based Systems (KB4039384)2017-09 Security Only Quality Update for Windows 7 for x64-based Systems (KB4038779)2017-09 Security Only Quality Update for Windows 8.1 for x86-based Systems (KB4038793)2017-09 Security Only Quality Update for Windows 7 for x86-based Systems (KB4038779)2017-09 Security Only Quality Update for Windows Embedded 8 Standard for x86-based Systems (KB4038786) | Sep 12, 2017 | Sep 12, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub