CVE-2017-8911 describes a critical integer underflow vulnerability in the unicode_to_utf8() function of tnef 1.4.14, which could allow an unauthenticated attacker to achieve arbitrary write operations. With a CVSS score of 9.8, this vulnerability poses a severe risk of complete compromise of confidentiality, integrity, and availability. While no public exploits, Metasploit modules, or Nuclei templates are currently available, and there is minimal community discussion, the high severity warrants immediate attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.4.14CPE matchmatch criteria | cpe:2.3:a:tnef_project:tnef:1.4.14:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.