CVE-2017-8727 is a memory corruption vulnerability within the Microsoft Windows Text Services Framework, affecting numerous Windows versions including Windows 7, 8.1, 10, and Server 2008, 2012, and 2016. This flaw allows an unauthenticated attacker to execute arbitrary code in the context of the current user, typically requiring user interaction. Rated with a CVSS score of 7.5 (HIGH), it carries a significant risk of full compromise of confidentiality, integrity, and availability. While no public exploit code is readily available (Metasploit, Nuclei, ExploitDB), it has garnered some community discussion and media coverage, indicating awareness. However, it is not currently listed on the CISA KEV catalog and is considered inactive on the Hot List.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:* | ||
1511CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1511:*:*:*:*:*:*:* | ||
1607CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:* | ||
1703CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1703:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_7:*:sp1:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.