CVE-2017-8487 is a remote code execution vulnerability in Windows OLE, specifically affecting Windows XP and Windows Server 2003, where opening a specially crafted file or program can lead to arbitrary code execution. This vulnerability is rated as High severity (CVSS 7.8) due to its low attack complexity and the potential for complete compromise of confidentiality, integrity, and availability, requiring user interaction to trigger. While not listed in CISA's KEV catalog, exploit intelligence indicates a memory disclosure exploit (EDB-42211) exists, and the vulnerability garnered significant community discussion and media coverage, particularly concerning emergency patches for older, unsupported Windows versions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2003:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_xp:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.