CVE-2017-8737 is a remote code execution vulnerability in the Microsoft Windows PDF Library, affecting Windows 8.1, RT 8.1, Server 2012/R2, and Windows 10/Server 2016. This memory handling flaw allows an attacker to execute arbitrary code in the context of the current user. With a CVSS score of 7.5 (High), it requires user interaction (UI:R) and has high impact on confidentiality, integrity, and availability (C:H/I:H/A:H), but a high attack complexity (AC:H). While not actively exploited (KEV: No) and lacking public exploit code, its high EPSS and FAUCET scores indicate significant potential risk, and it received some media and community attention at the time of disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_8.1:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_rt_8.1:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:* | ||
r2CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.