CVE-2017-0027

Description

Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, and Excel Services on SharePoint Server 2013 SP1 allow remote attackers to obtain sensitive information from process memory via a crafted Office document, aka Microsoft Office Information Disclosure Vulnerability.

Risk Information

Base Score
4.7
MODERATE
Vector
CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
29.737

Associated Vulnerability

VulnerabilityOS Platform
Microsoft SharePoint Elevation of Privilege Vulnerability for Microsoft Office Compatibility Pack Service Pack 3 (KB3178677)Windows
Microsoft SharePoint Elevation of Privilege Vulnerability for Microsoft Office Excel Viewer 2007 (KB3178680)Windows
Microsoft SharePoint Elevation of Privilege Vulnerability for Microsoft Office Excel 2007 (KB3178676)Windows
Microsoft SharePoint Elevation of Privilege Vulnerability for Microsoft Office 2010 (KB3178686) 64-Bit EditionWindows
Microsoft SharePoint Elevation of Privilege Vulnerability for Microsoft Office 2010 (KB3178686) 32-Bit EditionWindows
Microsoft SharePoint Elevation of Privilege Vulnerability for Word Viewer (KB3178694)Windows
Microsoft SharePoint Elevation of Privilege Vulnerability for Microsoft Word 2016 (KB3178674) 64-Bit EditionWindows
Microsoft SharePoint Elevation of Privilege Vulnerability for Microsoft Word 2016 (KB3178674) 32-Bit EditionWindows
Microsoft SharePoint Elevation of Privilege Vulnerability for Microsoft Office Word 2007 (KB3178683)Windows
Microsoft SharePoint Elevation of Privilege Vulnerability for Microsoft Word 2013 (KB3172464) 64-Bit EditionWindows
Microsoft SharePoint Elevation of Privilege Vulnerability for Microsoft Word 2013 (KB3172464) 32-Bit EditionWindows
Microsoft SharePoint Elevation of Privilege Vulnerability for Microsoft Word 2010 (KB3178687) 32-Bit EditionWindows
Microsoft SharePoint Elevation of Privilege Vulnerability for Microsoft Excel 2010 (KB3178690) 64-Bit EditionWindows
Microsoft SharePoint Elevation of Privilege Vulnerability for Microsoft Excel 2010 (KB3178690) 32-Bit EditionWindows
Microsoft SharePoint Elevation of Privilege Vulnerability for Microsoft Excel 2016 (KB3178673) 64-Bit EditionWindows
Microsoft SharePoint Elevation of Privilege Vulnerability for Microsoft Excel 2016 (KB3178673) 32-Bit EditionWindows
Microsoft SharePoint Elevation of Privilege Vulnerability for Microsoft Excel 2013 (KB3172542) 64-Bit EditionWindows
Microsoft SharePoint Elevation of Privilege Vulnerability for Microsoft Excel 2013 (KB3172542) 32-Bit EditionWindows
Microsoft SharePoint Elevation of Privilege Vulnerability for Microsoft Office Web Apps Server 2013 (KB3172457)Windows
Microsoft Excel Information Disclosure Vulnerability for Microsoft SharePoint Server 2010 (KB3178685)Windows
Microsoft Excel Information Disclosure Vulnerability for Microsoft SharePoint Enterprise Server 2013 (KB3172431)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-22024Security Update for Microsoft Office Compatibility Pack Service Pack 3 (KB3178677)
PATCH-22025Security Update for Microsoft Office Excel Viewer 2007 (KB3178680)
PATCH-22010Security Update for Microsoft Office Excel 2007 (KB3178676)
PATCH-22011Security Update for Microsoft Office 2010 (KB3178686) 64-Bit Edition
PATCH-22012Security Update for Microsoft Office 2010 (KB3178686) 32-Bit Edition
PATCH-22026Security Update for Word Viewer (KB3178694)
PATCH-22137Security Update for Microsoft Office Word 2007 (KB3178683)
PATCH-22019Security Update for Microsoft Word 2013 (KB3172464) 64-Bit Edition
PATCH-22018Security Update for Microsoft Word 2013 (KB3172464) 32-Bit Edition
PATCH-22015Security Update for Microsoft Word 2010 (KB3178687) 32-Bit Edition
PATCH-22014Security Update for Microsoft Excel 2010 (KB3178690) 64-Bit Edition
PATCH-22013Security Update for Microsoft Excel 2010 (KB3178690) 32-Bit Edition
PATCH-22021Security Update for Microsoft Excel 2016 (KB3178673) 64-Bit Edition
PATCH-22020Security Update for Microsoft Excel 2016 (KB3178673) 32-Bit Edition
PATCH-22017Security Update for Microsoft Excel 2013 (KB3172542) 64-Bit Edition
PATCH-22016Security Update for Microsoft Excel 2013 (KB3172542) 32-Bit Edition
PATCH-22136Security Update for Microsoft Office Web Apps Server 2013 (KB3172457)
PATCH-22134Security Update for Microsoft SharePoint Enterprise Server 2013 (KB3172431)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234