First published: Wed Sep 13 2017(Updated: )
Windows Uniscribe in Microsoft Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Office 2007 SP3; Office 2010 SP2; Word Viewer; Office for Mac 2011 and 2016; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Lync 2010 Attendee; and Live Meeting 2007 Add-in and Console allows an attacker to execute code remotely via a specially crafted website or a specially crafted document or email attachment, aka "Microsoft Graphics Component Remote Code Execution."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Live Meeting | =2007 | |
Microsoft Lync 2010 | =2010 | |
Microsoft Lync 2010 | =2010 | |
Microsoft Lync 2010 | =2013-sp1 | |
Microsoft Office | =sp3 | |
Microsoft Office | =sp2 | |
Microsoft Office Web Apps | =2010-sp2 | |
Microsoft Word Viewer | ||
Microsoft Skype for Business | =2016 | |
Microsoft Windows 7 | =sp1 | |
Microsoft Windows Server | =sp2 | |
Microsoft Windows Server | =sp2 | |
Microsoft Windows Server | =r2-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-8696 has a critical severity rating, indicating a serious risk to affected systems.
To mitigate CVE-2017-8696, apply the latest security updates provided by Microsoft for all affected software.
CVE-2017-8696 affects various Microsoft products, including Windows Server, Office 2007 and 2010, Lync, and Skype for Business.
CVE-2017-8696 is a vulnerability in the Windows Uniscribe component that could allow remote code execution.
Currently, no official workaround exists for CVE-2017-8696, so immediate patching is recommended.