60
CVE-2017-11854
—CVSS 3.0
8.8 high
EPSS
8%p95
Published
()
Modified
Description
Microsoft Word 2007 Service Pack 3, Microsoft Word 2010 Service Pack 2, Microsoft Office 2010 Service Pack 2, and Microsoft Office Compatibility Pack Service Pack 3 allow an attacker to run arbitrary code in the context of the current user by failing to properly handle objects in memory, aka "Microsoft Word Memory Corruption Vulnerability".
- Vendors
- microsoft
- Products
- office, office compatibility pack, word
- Weakness
- CWE-119
- Vector
- CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H