CVE-2017-8550

Description

A remote code execution vulnerability exists in Skype for Business when the software fails to sanitize specially crafted content, aka Skype for Business Remote Code Execution Vulnerability.

Risk Information

Base Score
5.4
MODERATE
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
EPSS Score
Exploitation Probability
12.38

Associated Vulnerability

VulnerabilityOS Platform
Windows Uniscribe Remote Code Execution Vulnerability for Microsoft Office 2007 suites (KB3191837)Windows
Windows Uniscribe Remote Code Execution Vulnerability for Microsoft Office 2010 (KB3191844) 64-Bit EditionWindows
Windows Uniscribe Remote Code Execution Vulnerability for Microsoft Office 2010 (KB3191844) 32-Bit EditionWindows
Windows Uniscribe Remote Code Execution Vulnerability for Word Viewer (KB3203427)Windows
Windows Uniscribe Remote Code Execution Vulnerability for Microsoft Office 2007 suites (KB3191828)Windows
Windows Uniscribe Remote Code Execution Vulnerability for Microsoft Office 2010 (KB3191848) 64-Bit EditionWindows
Windows Uniscribe Remote Code Execution Vulnerability for Microsoft Office 2010 (KB3191848) 32-Bit EditionWindows
Microsoft Outlook Security Feature Bypass Vulnerability for Microsoft Outlook 2016 (KB3191932) 64-Bit EditionWindows
Microsoft Outlook Security Feature Bypass Vulnerability for Microsoft Outlook 2016 (KB3191932) 32-Bit EditionWindows
Microsoft Outlook Security Feature Bypass Vulnerability for Microsoft Outlook 2013 (KB3191938) 64-Bit EditionWindows
Microsoft Outlook Security Feature Bypass Vulnerability for Microsoft Outlook 2013 (KB3191938) 32-Bit EditionWindows
Microsoft Office Remote Code Execution Vulnerability for Microsoft Office Compatibility Pack Service Pack 3 (KB3203438)Windows
Microsoft Office Remote Code Execution Vulnerability for Microsoft Office 2013 (KB3162051) 64-Bit EditionWindows
Microsoft Office Remote Code Execution Vulnerability for Microsoft Office 2013 (KB3162051) 32-Bit EditionWindows
Microsoft Office Remote Code Execution Vulnerability for Microsoft Office 2013 (KB3203386) 64-Bit Edition - Petya ransomware attack (CVE-2017-0199)Windows
Microsoft Office Remote Code Execution Vulnerability for Microsoft Office 2013 (KB3203386) 32-Bit Edition - Petya ransomware attack (CVE-2017-0199)Windows
Microsoft Office Remote Code Execution Vulnerability for Microsoft Office 2016 (KB3178667) 64-Bit EditionWindows
Microsoft Office Remote Code Execution Vulnerability for Microsoft Office 2016 (KB3178667) 32-Bit EditionWindows
Microsoft Office Remote Code Execution Vulnerability for Microsoft Office 2016 (KB3191882) 64-Bit EditionWindows
Microsoft Office Remote Code Execution Vulnerability for Microsoft Office 2016 (KB3191882) 32-Bit EditionWindows
Microsoft Office Remote Code Execution Vulnerability for Microsoft Office 2010 (KB3203463) 64-Bit EditionWindows
Microsoft Office Remote Code Execution Vulnerability for Microsoft Office 2010 (KB3203463) 32-Bit EditionWindows
Microsoft Office Remote Code Execution Vulnerability for Microsoft Office 2010 (KB3118389) 64-Bit EditionWindows
Microsoft Office Remote Code Execution Vulnerability for Microsoft Office 2010 (KB3118389) 32-Bit EditionWindows
Microsoft Office Remote Code Execution Vulnerability for Microsoft Office Word 2007 (KB3203441)Windows
Microsoft Office Remote Code Execution Vulnerability for Microsoft Word 2013 (KB3203393) 64-Bit EditionWindows
Microsoft Office Remote Code Execution Vulnerability for Microsoft Word 2013 (KB3203393) 32-Bit EditionWindows
Microsoft Office Remote Code Execution Vulnerability for Microsoft Word 2010 (KB3203464) 64-Bit EditionWindows
Microsoft Office Remote Code Execution Vulnerability for Microsoft Word 2010 (KB3203464) 32-Bit EditionWindows
Microsoft Office Remote Code Execution Vulnerability for Microsoft Office 2013 (KB3203392) 64-Bit EditionWindows
Microsoft Office Remote Code Execution Vulnerability for Microsoft Office 2013 (KB3203392) 32-Bit EditionWindows
Microsoft PowerPoint Remote Code Exectuion Vulnerability for Microsoft Office PowerPoint 2007 (KB3127888)Windows
Microsoft Office Remote Code Execution Vulnerability for Microsoft Office 2007 suites (KB3118304)Windows
Microsoft Office Remote Code Execution Vulnerability for Microsoft Office 2016 (KB3191944) 32-Bit EditionWindows
Microsoft Office Remote Code Execution Vulnerability for Microsoft Office 2016 (KB3191944) 64-Bit EditionWindows
Microsoft Office Remote Code Execution Vulnerability for Microsoft Office 2016 (KB3203383) 32-Bit EditionWindows
Microsoft Office Remote Code Execution Vulnerability for Microsoft Office 2016 (KB3203383) 64-Bit EditionWindows
Microsoft Office Remote Code Execution Vulnerability for Microsoft Office 2010 (KB3203461) 32-Bit EditionWindows
Microsoft Office Remote Code Execution Vulnerability for Microsoft Office 2010 (KB3203461) 64-Bit EditionWindows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-22606Security Update for Microsoft Office 2007 suites (KB3191837)
PATCH-22620Security Update for Microsoft Office 2010 (KB3191844) 64-Bit Edition
PATCH-22619Security Update for Microsoft Office 2010 (KB3191844) 32-Bit Edition
PATCH-22631Security Update for Word Viewer (KB3203427)
PATCH-22605Security Update for Microsoft Office 2007 suites (KB3191828)
PATCH-22622Security Update for Microsoft Office 2010 (KB3191848) 64-Bit Edition
PATCH-22621Security Update for Microsoft Office 2010 (KB3191848) 32-Bit Edition
PATCH-22634Security Update for Microsoft Outlook 2016 (KB3191932) 64-Bit Edition
PATCH-22633Security Update for Microsoft Outlook 2016 (KB3191932) 32-Bit Edition
PATCH-22650Security Update for Microsoft Outlook 2013 (KB3191938) 64-Bit Edition
PATCH-22649Security Update for Microsoft Outlook 2013 (KB3191938) 32-Bit Edition
PATCH-22596Security Update for Microsoft Office Compatibility Pack Service Pack 3 (KB3203438)
PATCH-22604Security Update for Microsoft Office 2013 (KB3162051) 64-Bit Edition
PATCH-22603Security Update for Microsoft Office 2013 (KB3162051) 32-Bit Edition
PATCH-22601Security Update for Microsoft Office 2013 (KB3203386) 64-Bit Edition - Petya ransomware attack (CVE-2017-0199)
PATCH-22600Security Update for Microsoft Office 2013 (KB3203386) 32-Bit Edition - Petya ransomware attack (CVE-2017-0199)
PATCH-22610Security Update for Microsoft Office 2016 (KB3178667) 64-Bit Edition
PATCH-22609Security Update for Microsoft Office 2016 (KB3178667) 32-Bit Edition
PATCH-22612Security Update for Microsoft Office 2016 (KB3191882) 64-Bit Edition
PATCH-22611Security Update for Microsoft Office 2016 (KB3191882) 32-Bit Edition
PATCH-22628Security Update for Microsoft Office 2010 (KB3203463) 64-Bit Edition
PATCH-22627Security Update for Microsoft Office 2010 (KB3203463) 32-Bit Edition
PATCH-22630Security Update for Microsoft Office 2010 (KB3118389) 64-Bit Edition
PATCH-22629Security Update for Microsoft Office 2010 (KB3118389) 32-Bit Edition
PATCH-22638Security Update for Microsoft Office Word 2007 (KB3203441)
PATCH-22640Security Update for Microsoft Word 2013 (KB3203393) 64-Bit Edition
PATCH-22639Security Update for Microsoft Word 2013 (KB3203393) 32-Bit Edition
PATCH-22641Security Update for Microsoft Word 2010 (KB3203464) 32-Bit Edition
PATCH-22598Security Update for Microsoft Office 2013 (KB3203392) 64-Bit Edition
PATCH-22597Security Update for Microsoft Office 2013 (KB3203392) 32-Bit Edition
PATCH-22599Security Update for Microsoft Office PowerPoint 2007 (KB3127888)
PATCH-22607Security Update for Microsoft Office 2007 suites (KB3118304)
PATCH-22615Security Update for Microsoft Office 2016 (KB3191944) 32-Bit Edition
PATCH-22616Security Update for Microsoft Office 2016 (KB3191944) 64-Bit Edition
PATCH-22617Security Update for Microsoft Office 2016 (KB3203383) 32-Bit Edition
PATCH-22618Security Update for Microsoft Office 2016 (KB3203383) 64-Bit Edition
PATCH-22625Security Update for Microsoft Office 2010 (KB3203461) 32-Bit Edition
PATCH-22626Security Update for Microsoft Office 2010 (KB3203461) 64-Bit Edition

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234