CVE-2017-11935 is a remote code execution vulnerability affecting Microsoft Office 2016 Click-to-Run, stemming from how the software handles files in memory. This high-severity vulnerability (CVSS 7.8) requires user interaction, typically through opening a malicious file, but can lead to complete compromise of confidentiality, integrity, and availability. While no public exploits or Metasploit modules are available, the vulnerability has garnered some community discussion and media coverage, though it is not listed on CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2016:c2r:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.