CVE-2017-8570

HIGH KEV

Microsoft Office - Remote Code Execution

Title source: rule

Description

Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Microsoft Office Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0243.

Exploits (12)

exploitdb WORKING POC
by Rich Warren · localwindows
https://www.exploit-db.com/exploits/44263
nomisec WORKING POC 184 stars
by rxwx · client-side
https://github.com/rxwx/CVE-2017-8570
nomisec WORKING POC 67 stars
by temesgeny · client-side
https://github.com/temesgeny/ppsx-file-generator
nomisec WORKING POC 5 stars
by SwordSheath · client-side
https://github.com/SwordSheath/CVE-2017-8570
nomisec WORKING POC 2 stars
by Drac0nids · poc
https://github.com/Drac0nids/CVE-2017-8570
nomisec WORKING POC 1 stars
by erfze · client-side
https://github.com/erfze/CVE-2017-8570
nomisec WORKING POC
by sasqwatch · client-side
https://github.com/sasqwatch/CVE-2017-8570
nomisec WORKING POC
by MaxSecurity · client-side
https://github.com/MaxSecurity/Office-CVE-2017-8570
patchapalooza WORKING POC
by The-Real-TechLord · local
https://gitlab.com/The-Real-TechLord/CVE-2017-8570
patchapalooza WORKING POC
by hz9511 · poc
https://gitee.com/hz9511/CVE-2017-8570_ppt
patchapalooza WORKING POC
by hz9511 · poc
https://gitee.com/hz9511/CVE-2017-8570

Scores

CVSS v3 7.8
EPSS 0.9422
EPSS Percentile 99.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CISA KEV 2022-02-25
VulnCheck KEV 2017-12-01
InTheWild.io 2021-06-24
ENISA EUVD EUVD-2017-17520
Status published
Products (5)
microsoft/office 2007 sp3
microsoft/office 2010 sp2
microsoft/office 2013 sp1 (2 CPE variants)
microsoft/office 2016 (2 CPE variants)
Microsoft Corporation/Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, and Microsoft Office 2016. Microsoft Office
Published Jul 11, 2017
KEV Added Feb 25, 2022
Tracked Since Feb 18, 2026