Junglewise Threat Intelligence

CVE-2017-8570: Microsoft Office Remote Code Execution Vulnerability

CVE-2017-8570 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-02-25

Technologies: Microsoft Office, Microsoft Office 2016. Vendors: Microsoft.

Executive brief

A remote code execution vulnerability exists in Microsoft Office when the software fails to properly handle objects in memory. An attacker could exploit this by convincing a user to open a specially crafted file, potentially leading to full system compromise.

Affected products

  • Microsoft Office 2007 Service Pack 3
  • Microsoft Office 2010 Service Pack 2
  • Microsoft Office 2013 Service Pack 1
  • Microsoft Office 2013 RT Service Pack 1
  • Microsoft Office 2016 All versions

Timeline

  • 2017-07-11: disclosed: Initial publication of vulnerability details and patches.
  • 2022-02-25: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog.

Related threats