CVE-2017-11935: Buffer Overflow
Published Dec 12, 2017
·Updated
Microsoft Office 2016 Click-to-Run (C2R) allows a remote code execution vulnerability due to the way files are handled in memory, aka "Microsoft Excel Remote Code Execution Vulnerability".
Affected Software
1 affected component
Microsoft Office=2016-c2r
Remediation
Event History
Dec 12, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-11935?
CVE-2017-11935 is classified as a critical remote code execution vulnerability.
2
How can I fix CVE-2017-11935?
To fix CVE-2017-11935, ensure that you apply the latest security updates provided by Microsoft for Office 2016 Click-to-Run.
3
What types of attacks can exploit CVE-2017-11935?
CVE-2017-11935 can be exploited through malicious Excel files that are opened by a user.
4
Which versions of Microsoft Office are affected by CVE-2017-11935?
CVE-2017-11935 affects Microsoft Office 2016 Click-to-Run (C2R) specifically.
5
What are the potential consequences of CVE-2017-11935 being exploited?
Exploitation of CVE-2017-11935 may allow an attacker to execute arbitrary code on the victim's machine.