First published: Tue Dec 12 2017(Updated: )
Microsoft Office 2016 Click-to-Run (C2R) allows a remote code execution vulnerability due to the way files are handled in memory, aka "Microsoft Excel Remote Code Execution Vulnerability".
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office | =2016-c2r |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-11935 is classified as a critical remote code execution vulnerability.
To fix CVE-2017-11935, ensure that you apply the latest security updates provided by Microsoft for Office 2016 Click-to-Run.
CVE-2017-11935 can be exploited through malicious Excel files that are opened by a user.
CVE-2017-11935 affects Microsoft Office 2016 Click-to-Run (C2R) specifically.
Exploitation of CVE-2017-11935 may allow an attacker to execute arbitrary code on the victim's machine.