CVE-2017-0108
Description
The Windows Graphics Component in Microsoft Office 2007 SP3; 2010 SP2; and Word Viewer; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Live Meeting 2007; Silverlight 5; Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; and Windows 7 SP1 allows remote attackers to execute arbitrary code via a crafted web site, aka Graphics Component Remote Code Execution Vulnerability. This vulnerability is different from that described in CVE-2017-0014.
Risk Information
Base Score
7.8
MODERATE
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
33.567
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Microsoft Browser Spoofing Vulnerability for Windows Server 2016 for x64-based Systems (KB4013429) - Cumulative | Windows |
| Microsoft Browser Spoofing Vulnerability for Windows 10 Version 1607 for x64-based Systems (KB4013429) - Cumulative | Windows |
| Microsoft Browser Spoofing Vulnerability for Windows 10 Version 1607 (KB4013429) - Cumulative | Windows |
| Internet Explorer Information Disclosure Vulnerability for Windows Server 2008 R2 for x64-based Systems -WannaCrypt Ransomware Worm (KB4012215) | Windows |
| Internet Explorer Information Disclosure Vulnerability for Windows 7 for x64-based Systems - WannaCrypt Ransomware Worm(KB4012215) | Windows |
| Internet Explorer Information Disclosure Vulnerability for Windows 7 - WannaCrypt Ransomware Worm(KB4012215) | Windows |
| Microsoft Browser Spoofing Vulnerability for Windows 10 for x64-based Systems (KB4012606) - Cumulative | Windows |
| Internet Explorer Information Disclosure Vulnerability for Windows Server 2012 R2- WannaCrypt Ransomware Worm(KB4012216) | Windows |
| Internet Explorer Information Disclosure Vulnerability for Windows 8.1 for x64-based Systems - WannaCrypt Ransomware Worm(KB4012216) | Windows |
| Internet Explorer Information Disclosure Vulnerability for Windows 8.1 - WannaCrypt Ransomware Worm(KB4012216) | Windows |
| Windows Uniscribe Information Disclosure Vulnerability for Windows 7 for x64-based Systems - WannaCrypt Ransomware Worm(KB4012212) | Windows |
| Windows Uniscribe Information Disclosure Vulnerability for Windows 7 - WannaCrypt Ransomware Worm(KB4012212) | Windows |
| Windows Uniscribe Information Disclosure Vulnerability for Windows Server 2008 R2 for x64-based Systems - WannaCrypt Ransomware Worm(KB4012212) | Windows |
| Microsoft Browser Spoofing Vulnerability for Windows 10 Version 1511 for x64-based Systems (KB4013198) - Cumulative | Windows |
| Microsoft Browser Spoofing Vulnerability for Windows 10 Version 1511 (KB4013198) - Cumulative | Windows |
| Windows Uniscribe Information Disclosure Vulnerability for Windows 8.1 for x64-based Systems - WannaCrypt Ransomware Worm(KB4012213) | Windows |
| Windows Uniscribe Information Disclosure Vulnerability for Windows 8.1 - WannaCrypt Ransomware Worm(KB4012213) | Windows |
| Windows Uniscribe Information Disclosure Vulnerability for Windows Server 2012 R2 - WannaCrypt Ransomware Worm (KB4012213) | Windows |
| Windows Uniscribe Information Disclosure Vulnerability for Windows Server 2012 - WannaCrypt Ransomware Worm(KB4012214) | Windows |
| Windows Uniscribe Information Disclosure Vulnerability for Windows Embedded 8 Standard for x64-based Systems (KB4012214) | Windows |
| Windows Uniscribe Information Disclosure Vulnerability for Windows Embedded 8 Standard (KB4012214) | Windows |
| Windows Graphics Component Remote Code Execution Vulnerability for Windows Server 2008 for x64-based Systems (KB4012497) | Windows |
| Windows Graphics Component Remote Code Execution Vulnerability for Windows Server 2008 (KB4012497) | Windows |
| Windows Graphics Component Remote Code Execution Vulnerability for Windows Vista for x64-based Systems (KB4012497) | Windows |
| Windows Graphics Component Remote Code Execution Vulnerability for Windows Vista (KB4012497) | Windows |
| Windows Uniscribe Information Disclosure Vulnerability for Windows Server 2008 for x64-based Systems (KB4012583) | Windows |
| Windows Uniscribe Information Disclosure Vulnerability for Windows Server 2008 (KB4012583) | Windows |
| Windows Uniscribe Information Disclosure Vulnerability for Windows Vista for x64-based Systems (KB4012583) | Windows |
| Windows Uniscribe Information Disclosure Vulnerability for Windows Vista (KB4012583) | Windows |
| Windows Uniscribe Information Disclosure Vulnerability for Windows 8 for x64-based Systems (KB4012583) | Windows |
| Windows Uniscribe Information Disclosure Vulnerability for Windows 8 (KB4012583) | Windows |
| Windows Uniscribe Information Disclosure Vulnerability for Windows Server 2003 for x64-based Systems (KB4012583) | Windows |
| Windows Uniscribe Information Disclosure Vulnerability for Windows Server 2003 (KB4012583) | Windows |
| Windows Uniscribe Information Disclosure Vulnerability for Windows XP for x64-based Systems (KB4012583) | Windows |
| Windows Uniscribe Information Disclosure Vulnerability for Windows XP Service Pack 3 (KB4012583) | Windows |
| Windows Graphics Component Remote Code Execution Vulnerability for Windows Server 2008 for x64-based Systems (KB4012584) | Windows |
| Windows Graphics Component Remote Code Execution Vulnerability for Windows Server 2008 (KB4012584) | Windows |
| Windows Graphics Component Remote Code Execution Vulnerability for Windows Vista for x64-based Systems (KB4012584) | Windows |
| Windows Graphics Component Remote Code Execution Vulnerability for Windows Vista (KB4012584) | Windows |
| Windows Graphics Component Remote Code Execution Vulnerability for Microsoft Office 2007 suites (KB3127945) | Windows |
| Windows Graphics Component Remote Code Execution Vulnerability for Microsoft Office 2010 (KB3127958) 64-Bit Edition | Windows |
| Windows Graphics Component Remote Code Execution Vulnerability for Microsoft Office 2010 (KB3127958) 32-Bit Edition | Windows |
| Windows Graphics Component Remote Code Execution Vulnerability for Word Viewer (KB3178693) | Windows |
| Windows Graphics Component Remote Code Execution Vulnerability for Skype for Business 2016 (KB3178656) 64-Bit Edition | Windows |
| Windows Graphics Component Remote Code Execution Vulnerability for Skype for Business 2016 (KB3178656) 32-Bit Edition | Windows |
| Windows Graphics Component Remote Code Execution Vulnerability for Skype for Business 2015 (KB3172539) 64-Bit Edition | Windows |
| Windows Graphics Component Remote Code Execution Vulnerability for Skype for Business 2015 (KB3172539) 32-Bit Edition | Windows |
| Windows Graphics Component Remote Code Execution Vulnerability for Microsoft Silverlight (KB4013867) | Windows |
| Windows Graphics Component Remote Code Execution Vulnerability for Microsoft Silverlight (KB4013867) x64 bases systems | Windows |
| Windows Graphics Component Remote Code Execution Vulnerability for Microsoft Office 2007 suites (KB3141535) | Windows |
| Windows Graphics Component Remote Code Execution Vulnerability for Word Viewer (KB3178653) | Windows |
Patch Details
Click to see the patches provided by ManageEngine for this CVE
| Patch ID | Patch Description |
|---|---|
| PATCH-22054 | Cumulative Update for Windows Server 2016 for x64-based Systems (KB4013429) |
| PATCH-22053 | Cumulative Update for Windows 10 Version 1607 for x64-based Systems (KB4013429) |
| PATCH-22052 | Cumulative Update for Windows 10 Version 1607 (KB4013429) |
| PATCH-22046 | March, 2017 Security Monthly Quality Rollup for Windows Server 2008 R2 for x64-based Systems -WannaCrypt Ransomware Worm (KB4012215) |
| PATCH-22045 | March, 2017 Security Monthly Quality Rollup for Windows 7 for x64-based Systems - WannaCrypt Ransomware Worm(KB4012215) |
| PATCH-22044 | March, 2017 Security Monthly Quality Rollup for Windows 7 - WannaCrypt Ransomware Worm(KB4012215) |
| PATCH-22049 | Cumulative Update for Windows 10 for x64-based Systems (KB4012606) |
| PATCH-22149 | March, 2017 Security Monthly Quality Rollup for Windows Server 2012 R2- WannaCrypt Ransomware Worm(KB4012216) |
| PATCH-22148 | March, 2017 Security Monthly Quality Rollup for Windows 8.1 for x64-based Systems - WannaCrypt Ransomware Worm(KB4012216) |
| PATCH-22047 | March, 2017 Security Monthly Quality Rollup for Windows 8.1 - WannaCrypt Ransomware Worm(KB4012216) |
| PATCH-22063 | March, 2017 Security Only Quality Update for Windows 7 for x64-based Systems - WannaCrypt Ransomware Worm(KB4012212) |
| PATCH-22062 | March, 2017 Security Only Quality Update for Windows 7 - WannaCrypt Ransomware Worm(KB4012212) |
| PATCH-22064 | March, 2017 Security Only Quality Update for Windows Server 2008 R2 for x64-based Systems - WannaCrypt Ransomware Worm(KB4012212) |
| PATCH-22051 | Cumulative Update for Windows 10 Version 1511 for x64-based Systems (KB4013198) |
| PATCH-22050 | Cumulative Update for Windows 10 Version 1511 (KB4013198) |
| PATCH-22066 | March, 2017 Security Only Quality Update for Windows 8.1 for x64-based Systems - WannaCrypt Ransomware Worm(KB4012213) |
| PATCH-22065 | March, 2017 Security Only Quality Update for Windows 8.1 - WannaCrypt Ransomware Worm(KB4012213) |
| PATCH-22067 | March, 2017 Security Only Quality Update for Windows Server 2012 R2 - WannaCrypt Ransomware Worm (KB4012213) |
| PATCH-22070 | March, 2017 Security Only Quality Update for Windows Server 2012 - WannaCrypt Ransomware Worm(KB4012214) |
| PATCH-22108 | Security Update for Windows Server 2008 for x64-based Systems (KB4012497) |
| PATCH-22106 | Security Update for Windows Server 2008 (KB4012497) |
| PATCH-22107 | Security Update for Windows Vista for x64-based Systems (KB4012497) |
| PATCH-22105 | Security Update for Windows Vista (KB4012497) |
| PATCH-22086 | Security Update for Windows Server 2008 for x64-based Systems (KB4012583) |
| PATCH-22084 | Security Update for Windows Server 2008 (KB4012583) |
| PATCH-22085 | Security Update for Windows Vista for x64-based Systems (KB4012583) |
| PATCH-22083 | Security Update for Windows Vista (KB4012583) |
| PATCH-22688 | Security Update for Windows 8 for x64-based Systems (KB4012583) |
| PATCH-22685 | Security Update for Windows 8 (KB4012583) |
| PATCH-22687 | Security Update for Windows Server 2003 for x64-based Systems (KB4012583) |
| PATCH-22684 | Security Update for Windows Server 2003 (KB4012583) |
| PATCH-22686 | Security Update for Windows XP for x64-based Systems (KB4012583) |
| PATCH-22683 | Security Update for Windows XP Service Pack 3 (KB4012583) |
| PATCH-22090 | Security Update for Windows Server 2008 for x64-based Systems (KB4012584) |
| PATCH-22088 | Security Update for Windows Server 2008 (KB4012584) |
| PATCH-22089 | Security Update for Windows Vista for x64-based Systems (KB4012584) |
| PATCH-22087 | Security Update for Windows Vista (KB4012584) |
| PATCH-22161 | Security Update for Microsoft Office 2007 suites (KB3127945) |
| PATCH-22160 | Security Update for Microsoft Office 2010 (KB3127958) 64-Bit Edition |
| PATCH-22159 | Security Update for Microsoft Office 2010 (KB3127958) 32-Bit Edition |
| PATCH-22154 | Security Update for Skype for Business 2016 (KB3178656) 64-Bit Edition |
| PATCH-22091 | Security Update for Skype for Business 2016 (KB3178656) 32-Bit Edition |
| PATCH-22156 | Security Update for Skype for Business 2015 (KB3172539) 64-Bit Edition |
| PATCH-22155 | Security Update for Skype for Business 2015 (KB3172539) 32-Bit Edition |
| PATCH-22162 | Security Update for Microsoft Office 2007 suites (KB3141535) |
| PATCH-22164 | Security Update for Word Viewer (KB3178653) |
References
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234