CVE-2017-8718 is a remote code execution vulnerability in the Microsoft JET Database Engine, affecting numerous Windows versions including Windows 7, 8.1, 10, and various Server editions. This vulnerability, stemming from improper memory object handling, allows an attacker to gain full control of an affected system. Rated with a CVSS score of 7.8 (High), it requires user interaction (UI:R) but has low attack complexity (AC:L), leading to high confidentiality, integrity, and availability impacts. While no public exploit code (Metasploit, Nuclei, ExploitDB) is readily available and it's not listed in CISA's KEV catalog, its high FAUCET Risk Score of 94/100, community discussion, and media coverage indicate significant concern.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:* | ||
1511CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:* | ||
1607CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:* | ||
1703CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1703:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_7:*:sp1:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.