CVE-2017-11854: Buffer Overflow
Microsoft Word 2007 Service Pack 3, Microsoft Word 2010 Service Pack 2, Microsoft Office 2010 Service Pack 2, and Microsoft Office Compatibility Pack Service Pack 3 allow an attacker to run arbitrary code in the context of the current user by failing to properly handle objects in memory, aka "Microsoft Word Memory Corruption Vulnerability".
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2017-11854?
CVE-2017-11854 is a vulnerability in Microsoft Word and Microsoft Office that allows an attacker to run arbitrary code in the context of the current user.
How severe is CVE-2017-11854?
CVE-2017-11854 has a severity rating of 8.8 (critical).
Which software versions are affected by CVE-2017-11854?
Microsoft Word 2007 Service Pack 3, Microsoft Word 2010 Service Pack 2, Microsoft Office 2010 Service Pack 2, and Microsoft Office Compatibility Pack Service Pack 3 are affected by CVE-2017-11854.
How can an attacker exploit CVE-2017-11854?
An attacker can exploit CVE-2017-11854 by failing to properly handle objects in memory, allowing them to run arbitrary code in the context of the current user.
Are there any fixes or patches available for CVE-2017-11854?
Yes, patches and fixes are available for CVE-2017-11854. It is recommended to update the affected software to the latest version.