CVE-2017-8742 is a remote code execution vulnerability affecting multiple Microsoft PowerPoint and SharePoint products, including various Office versions and SharePoint Server 2013/2016. This flaw arises from improper memory handling, allowing an attacker to execute arbitrary code. With a CVSS score of 7.8 (High), it presents a significant risk, requiring user interaction (e.g., opening a malicious file) but offering high impact on confidentiality, integrity, and availability. While no public exploit code or active exploitation is confirmed, its high FAUCET Risk Score of 96/100 and mentions in community discussions indicate its potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:office_compatibility_pack:-:sp3:*:*:*:*:*:* | ||
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:office_web_apps:2010:sp2:*:*:*:*:*:* | ||
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:office_web_apps_server:2013:sp1:*:*:*:*:*:* | ||
2007CPE matchmatch criteria | cpe:2.3:a:microsoft:powerpoint:2007:sp3:*:*:*:*:*:* | ||
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:powerpoint:2010:sp2:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.