vulnerability

Microsoft CVE-2017-0029: Microsoft Office Denial of Service Vulnerability

Severity
4
CVSS
(AV:N/AC:M/Au:N/C:N/I:N/A:P)
Published
Mar 14, 2017
Added
Mar 14, 2017
Modified
Aug 23, 2019

Description

A denial of service vulnerability exists when a specially crafted file is opened in Microsoft Office. An attacker who successfully exploited the vulnerability could cause Office to stop responding. Note that the denial of service would not allow an attacker to execute code or to elevate the attacker's user rights.
For an attack to be successful, this vulnerability requires that a user open a specially crafted file with an affected version of Microsoft Office. In an email attack scenario, an attacker could exploit the vulnerability by sending a specially crafted file to the user and by convincing the user to open the file.
The security update addresses the vulnerability by correcting how Microsoft Office handles objects in memory.

Solutions

msft-kb3172464-0172f85d-1946-485d-8918-abea257c63dcmsft-kb3172464-a04a51ad-21f5-4cd5-9072-6a47ae4dc956msft-kb3178686-1d62f900-6efa-4f58-8839-b19acc974dbemsft-kb3178686-d2b33545-2974-4477-ba45-e332c0f7b69cmsft-kb3178687-382e4ca2-ddf4-4dc1-8b40-0c02eabbbb27msft-kb3178687-726adfc6-4ac9-4409-bdab-2892b7058e78
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.