#VU9647 Out-of-bounds read in Microsoft Office and Microsoft Office for macOS - CVE-2017-11934

 

#VU9647 Out-of-bounds read in Microsoft Office and Microsoft Office for macOS - CVE-2017-11934

Published: December 12, 2017 / Updated: December 12, 2017


Vulnerability identifier: #VU9647
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2017-11934
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Microsoft Office
Microsoft Office for macOS
Software vendor:
Microsoft

Description

The vulnerability allows a remote attacker to obtain potentially sensitive information.

The vulnerability exists due to boundary error when processing PowerPoint files. A remote attacker can create a specially crafted PowerPoint file, trick the victim into opening it and obtain information  and gain access to potentially sensitive information, stored in memory.


Remediation

Install updates from vendor's website.

External links