CVE-2017-0197: Input Validation
Published Apr 12, 2017
·Updated
Microsoft OneNote 2007 SP3 and Microsoft OneNote 2010 SP2 allow remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office DLL Loading Vulnerability."
Affected Software
2 affected components
Microsoft OneNote=2007-sp3
Microsoft OneNote=2010-sp2
Remediation
Event History
Apr 12, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-0197?
CVE-2017-0197 is considered to have a critical severity rating due to its potential for remote code execution.
2
How do I fix CVE-2017-0197?
To fix CVE-2017-0197, users should update Microsoft OneNote to the latest Service Pack for their version.
3
What versions of Microsoft OneNote are affected by CVE-2017-0197?
CVE-2017-0197 affects Microsoft OneNote 2007 SP3 and Microsoft OneNote 2010 SP2.
4
What types of attacks can occur due to CVE-2017-0197?
CVE-2017-0197 can allow remote attackers to execute arbitrary code via a specially crafted document.
5
Is user interaction required for CVE-2017-0197 to be exploited?
Yes, exploitation of CVE-2017-0197 typically requires the user to open a crafted document.