VYPR
High severity7.8NVD Advisory· Published Mar 17, 2017· Updated May 13, 2026

CVE-2017-0108

CVE-2017-0108

Description

The Windows Graphics Component in Microsoft Office 2007 SP3; 2010 SP2; and Word Viewer; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Live Meeting 2007; Silverlight 5; Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; and Windows 7 SP1 allows remote attackers to execute arbitrary code via a crafted web site, aka "Graphics Component Remote Code Execution Vulnerability." This vulnerability is different from that described in CVE-2017-0014.

Affected products

13
  • cpe:2.3:a:microsoft:live_meeting:2007:*:*:*:*:*:*:*
  • Microsoft/Lync2 versions
    cpe:2.3:a:microsoft:lync:2010:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:microsoft:lync:2010:*:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:lync:2013:sp1:*:*:*:*:*:*
  • Microsoft/Office2 versions
    cpe:2.3:a:microsoft:office:2007:sp3:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:microsoft:office:2007:sp3:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:office:2010:sp2:*:*:*:*:*:*
  • cpe:2.3:a:microsoft:silverlight:5.0:*:*:*:*:*:*:*
  • cpe:2.3:a:microsoft:skype_for_business:2016:*:*:*:*:*:*:*
  • cpe:2.3:a:microsoft:word_viewer:-:*:*:*:*:*:*:*
  • cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:*
  • cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*
    • cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:*
  • cpe:2.3:o:microsoft:windows_vista:-:sp2:*:*:*:*:*:*
  • Microsoft Corporation/Windows Graphics Componentv5
    Range: The Windows Graphics Component in Microsoft Office 2007 SP3; 2010 SP2; and Word Viewer; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Live Meeting 2007; Silverlight 5; Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; and Windows 7 SP1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.