CVE-2017-0003 is a memory corruption vulnerability affecting Microsoft Word 2016 and SharePoint Enterprise Server 2016, allowing remote attackers to execute arbitrary code through crafted documents. With a CVSS score of 7.8 (High), it requires user interaction (e.g., opening a malicious document) but can lead to complete compromise of confidentiality, integrity, and availability. While it has a high EPSS and FAUCET Risk Score, indicating significant potential impact, there is no known active exploitation, KEV entry, or public exploit code available in Metasploit, Nuclei, or ExploitDB. Despite this, it garnered notable community discussion and media coverage at the time of its disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:sharepoint_enterprise_server:2016:*:*:*:*:*:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:word:2016:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.