First published: Fri Mar 17 2017(Updated: )
Microsoft Office Compatibility Pack SP3, Excel 2007 SP3, Excel Viewer, and Excel Services on SharePoint Server 2007 SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability." This vulnerability is different from those described in CVE-2017-0006, CVE-2017-0019, CVE-2017-0020, CVE-2017-0030, CVE-2017-0031, and CVE-2017-0053.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office Excel | =2007-sp3 | |
Microsoft Office Excel Viewer | ||
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint | =sp3 | |
Microsoft SharePoint Server 2010 | =2007-sp3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-0052 is a critical vulnerability that allows remote attackers to execute arbitrary code or cause denial of service.
To fix CVE-2017-0052, ensure that you install the latest security updates for affected Microsoft products.
CVE-2017-0052 affects Microsoft Office Compatibility Pack SP3, Excel 2007 SP3, Excel Viewer, and SharePoint Server 2007 SP3.
CVE-2017-0052 can be exploited through crafted documents that lead to memory corruption.
Exploitation of CVE-2017-0052 can be relatively easy for attackers, as it only requires a crafted document to trigger the vulnerability.