CVE-2017-0108
35Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 50%
from disclosure to weapon3 days
Published on NVDMar 17
1st PoC+3d
exploitation probability
50%top 1% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
The Windows Graphics Component in Microsoft Office 2007 SP3; 2010 SP2; and Word Viewer; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Live Meeting 2007; Silverlight 5; Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; and Windows 7 SP1 allows remote attackers to execute arbitrary code via a crafted web site, aka "Graphics Component Remote Code Execution Vulnerability." This vulnerability is different from that described in CVE-2017-0014.
Affected products
Microsoft Corporation · Windows Graphics Componentpublic PoCs found — 3✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/41647githubgithub.com/homjxi0e/CVE-2017-0108★ 2cve_referencewww.exploit-db.com/exploits/41647/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.