CVE-2017-0029 is a denial of service vulnerability affecting Microsoft Office 2010 SP2, Word 2010 SP2, Word 2013 RT SP1, and Word 2016. An attacker can exploit this by crafting a malicious Office document, leading to an application hang. Rated Medium severity (CVSS 5.5), it requires user interaction (UI:R) to open the document, but has a high impact on availability (A:H). While no public exploit code (Metasploit, Nuclei, ExploitDB) is available and it's not in CISA's KEV catalog, its FAUCET Risk Score of 80/100 and mentions in community discussions and media coverage suggest it warrants attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2010:sp2:*:*:*:*:*:* | ||
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:word:2010:sp2:*:*:*:*:*:* | ||
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:word:2013:sp1:*:*:rt:*:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:word:2016:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.