Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerability · NVD

CVE-2017-11884

CVE-2017-11884, high severity (CVSS 7.8): 2 tracked apps concerned, all fixed or indeterminable on their current version.

Severity (CVSS)
7.8

NVD scale

Exploitation
9.5 %

EPSS, predicted over 30 days

Tracked apps
2
Still exposed
0

Microsoft Excel 2016 Click-to-Run (C2R) allows an attacker to run arbitrary code in the context of the current user by failing to properly handle objects in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11882.

Attack vector : Local No privileges required
Show raw CVSS vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS 9.49% above median percentile 95.1%

Tracked apps referencing this CVE

For each app: the affected range, the fixing version, and where the tracked app stands today.

Vulnerable CPE configurations (2)
Vendor Product Versions
microsoft excel
All platforms (wildcard)
-
microsoft excel
All platforms (wildcard)
-
View on NVD ↗ Advisory · portal.msrc.microsoft.com