First published: Thu Jun 15 2017(Updated: )
Windows PDF in Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows remote code execution if a user opens a specially crafted PDF file, aka "Windows PDF Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0291.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office Word | =2013-sp1 | |
Microsoft Office Word | =2013-sp1 | |
Microsoft Office Word | =2016 | |
Microsoft Windows 10 | ||
Microsoft Windows 10 | =1511 | |
Microsoft Windows 10 | =1607 | |
Microsoft Windows 10 | =1703 | |
Microsoft Windows 8.1 | ||
Microsoft Windows RT | ||
Microsoft Windows Server | ||
Microsoft Windows Server | =r2 | |
Microsoft Windows Server 2016 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-0292 has a critical severity rating due to its potential for remote code execution.
To fix CVE-2017-0292, ensure that all affected Microsoft products are updated with the latest security patches provided by Microsoft.
CVE-2017-0292 affects various versions of Microsoft Windows, including Windows 8.1, Windows 10, and Windows Server 2016, as well as specific editions of Microsoft Word.
CVE-2017-0292 can be exploited if a user opens a specially crafted PDF file, leading to potential remote code execution.
While the best solution is to apply the security updates, temporarily avoiding opening untrusted PDF files can mitigate the risk of CVE-2017-0292.