CVE-2017-0106 is a memory corruption vulnerability affecting Microsoft Excel 2007 SP3 and various versions of Microsoft Outlook (2010 SP2, 2013 SP1, 2016). It allows remote attackers to execute arbitrary code or cause a denial of service through a crafted document. With a CVSS score of 7.8 (High), this vulnerability requires user interaction (UI:R) but has low attack complexity (AC:L) and can lead to complete compromise of confidentiality, integrity, and availability (C:H/I:H/A:H). While not listed in KEV and lacking public exploit code in Metasploit or ExploitDB, media coverage indicates it has been used in cyber-espionage and malware distribution, suggesting active exploitation despite limited community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2007CPE matchmatch criteria | cpe:2.3:a:microsoft:outlook:2007:sp3:*:*:*:*:*:* | ||
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:outlook:2010:sp2:*:*:*:*:*:* | ||
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:outlook:2013:sp1:*:*:*:*:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:outlook:2016:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.