← back
CVE-2017-8570highunder attack

CVE-2017-8570

98Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA, has a public proof of concept and 2 threat group(s) use it.

ssvc Actcvss 7.8epss 86%
from disclosure to weapon13 days
Published on NVDJul 11
1st PoC+13d
CISA KEV+1690d
exploitation probability
86%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
2 group(s)17 public exploit(s)
Who exploits it2

Groups known to exploit this vulnerability (MITRE ATT&CK attribution).

Action required by CISAfederal deadline: 2022-08-25

Apply updates per vendor instructions.

In short

Microsoft Office has a flaw in how it manages data in memory that allows attackers to run malicious code on your computer by sending you a specially crafted file. This is dangerous because it can give attackers complete control of your system.

Technical detail

A memory handling vulnerability in Microsoft Office enables remote code execution when processing specially crafted documents. The attack vector is user interaction (opening a malicious file), with no additional privileges required. Successful exploitation results in arbitrary code execution in the context of the affected Office application.

Summary generated and translated by AI from the official description.
Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Microsoft Office Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0243.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.