CVE-2017-8691 is a remote code execution vulnerability affecting Windows 7 SP1 and Windows Server 2008 SP2/R2 SP1, where specially crafted embedded fonts can be mishandled by the Windows font library. This vulnerability carries a high CVSS score of 8.8, indicating a critical risk due to its network attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. While no public exploit code is readily available (Metasploit, Nuclei, ExploitDB), its high EPSS and FAUCET Risk Score suggest significant potential for exploitation. Community discussion and media coverage are limited, but the vulnerability was addressed in Microsoft's August Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_7:*:sp1:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2008:*:sp2:*:*:*:*:*:* | ||
r2CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.