CVE-2017-8743 is a remote code execution vulnerability affecting Microsoft PowerPoint 2016, SharePoint Enterprise Server 2016, and Office Online Server, stemming from improper memory handling. With a CVSS score of 7.8 (High), it requires user interaction (UI:R) but has low attack complexity (AC:L), allowing an attacker to gain high confidentiality, integrity, and availability impact (C:H/I:H/A:H) if exploited. While no public exploit code or Metasploit modules are available, its high EPSS score and mention in security news indicate significant potential risk, despite not being actively exploited in the wild or listed in CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:microsoft:office_online_server:*:*:*:*:*:*:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:powerpoint:2016:*:*:*:*:*:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.