CVE-2017-8570
HIGH KEVMicrosoft Office - Remote Code Execution
Title source: ruleDescription
Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Microsoft Office Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0243.
Exploits (12)
nomisec
WORKING POC
67 stars
by temesgeny · client-side
https://github.com/temesgeny/ppsx-file-generator
nomisec
WORKING POC
5 stars
by SwordSheath · client-side
https://github.com/SwordSheath/CVE-2017-8570
nomisec
WORKING POC
by MaxSecurity · client-side
https://github.com/MaxSecurity/Office-CVE-2017-8570
patchapalooza
WORKING POC
by The-Real-TechLord · local
https://gitlab.com/The-Real-TechLord/CVE-2017-8570
References (6)
Scores
CVSS v3
7.8
EPSS
0.9422
EPSS Percentile
99.9%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Details
CISA KEV
2022-02-25
VulnCheck KEV
2017-12-01
InTheWild.io
2021-06-24
ENISA EUVD
EUVD-2017-17520
Status
published
Products (5)
microsoft/office
2007 sp3
microsoft/office
2010 sp2
microsoft/office
2013 sp1 (2 CPE variants)
microsoft/office
2016 (2 CPE variants)
Microsoft Corporation/Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, and Microsoft Office 2016.
Microsoft Office
Published
Jul 11, 2017
KEV Added
Feb 25, 2022
Tracked Since
Feb 18, 2026