CVE-2017-8744 is a remote code execution vulnerability affecting Microsoft Excel and Excel Services across multiple versions (2007 SP3 to 2016). This memory corruption flaw allows an attacker to execute arbitrary code if a user opens a specially crafted file. With a CVSS score of 7.8 (High), it requires user interaction (UI:R) but has low attack complexity (AC:L) and can lead to high confidentiality, integrity, and availability impacts (C:H/I:H/A:H). While not listed in CISA's KEV catalog, there is no public exploit code available (Metasploit, Nuclei, ExploitDB: None), and community discussion and media coverage are minimal, suggesting it is not widely exploited or discussed.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2007CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2007:sp3:*:*:*:*:*:* | ||
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2010:sp2:*:*:*:*:*:* | ||
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2013:sp1:*:*:*:*:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2016:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.