CVE-2017-11854 is a memory corruption vulnerability in Microsoft Word 2007 SP3, Word 2010 SP2, Office 2010 SP2, and Office Compatibility Pack SP3, allowing arbitrary code execution in the context of the current user. Rated 8.8 HIGH (CVSSv3), it is a critical vulnerability with a network attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability, requiring user interaction. While not listed in CISA KEV and lacking public exploit code in Metasploit or ExploitDB, it has garnered some community discussion and media coverage, indicating awareness. Despite its age, its high FAUCET risk score of 91/100 suggests continued relevance.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2010:sp2:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:office_compatibility_pack:-:sp3:*:*:*:*:*:* | ||
2007CPE matchmatch criteria | cpe:2.3:a:microsoft:word:2007:sp3:*:*:*:*:*:* | ||
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:word:2010:sp2:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.