First published: Thu Jun 15 2017(Updated: )
A remote code execution vulnerability exists in Microsoft Office when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-8509, CVE-2017-8510, CVE-2017-8511, CVE-2017-0260, and CVE-2017-8506.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office | =2007-sp3 | |
Microsoft Office | =2010-sp2 | |
Microsoft Office | =2013-sp1 | |
Microsoft Office | =2013-sp1 | |
Microsoft Office | =2016 | |
Microsoft Office Online Server | =2016 | |
Microsoft Office Web Apps | =2010-sp2 | |
Microsoft Office Web Apps Server | =2013-sp1 | |
Microsoft SharePoint Enterprise Server | =2013-sp1 | |
Microsoft SharePoint Enterprise Server | =2016 | |
Microsoft Word Automation Services | ||
Microsoft SharePoint Server | =2010-sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-8512 is rated as critical due to its potential for remote code execution.
To fix CVE-2017-8512, update Microsoft Office to the latest security patches provided by Microsoft.
CVE-2017-8512 affects multiple versions of Microsoft Office including 2007, 2010, 2013, and 2016.
Yes, exploiting CVE-2017-8512 could lead to data theft as it allows remote execution of arbitrary code.
Detection of CVE-2017-8512 exploitation may include monitoring for unusual processes or network activity linked to Microsoft Office applications.