<< Back
CVE Number Vulnerability Product Severity Date
CVE-2017-8696 Microsoft Graphics Component Remote Code Execution Windows 7 Critical 13-09-2017

Technical Information

Brief overview of the risk:
A remote code execution vulnerability exists due to the way Windows Uniscribe handles objects in memory. An attacker who successfully exploited this vulnerability could take control of the affected system.

Detailed Information on the risk:

In a web-based attack scenario, an attacker could host a specially crafted website designed to exploit this vulnerability and then convince a user to view the website. An attacker would have no way to force users to view the attacker-controlled content. Instead, an attacker would have to convince users to take action, typically by getting them to click a link in an email or instant message that takes users to the attacker’s website, or by opening an attachment sent through email.

Further information on this exploit is available at : CVE-2017-8696
Microsoft Live Meeting 2007 Add-in
Microsoft Live Meeting 2007 Console
Microsoft Lync 2010 (32-bit)
Microsoft Lync 2010 (64-bit)
Microsoft Lync 2013 (32-bit) SP1
Microsoft Lync 2013 (64-bit) SP1
Microsoft Lync Basic 2013 (32-bit) SP1
Microsoft Lync Basic 2013 (64-bit) SP1
Microsoft Office 2007 SP3
Microsoft Office 2010 Service Pack 2 (32-bit editions)
Microsoft Office 2010 Service Pack 2 (64-bit editions)
Microsoft Office Web Apps 2010 SP2
Microsoft Office Word Viewer
Microsoft Skype for Business 2016 (32-bit)
Microsoft Skype for Business 2016 (64-bit)
Microsoft Skype for Business Basic 2016 (32-bit)
Microsoft Skype for Business Basic 2016 (64-bit)
Microsoft Windows 7 for 32-bit Systems SP1
Microsoft Windows 7 for x64-based Systems SP1
Microsoft Windows 8.1 for 32-bit Systems
Microsoft Windows Server 2008 R2 for Itanium-based Systems SP1
Microsoft Windows Server 2008 R2 for x64-based Systems SP1
Microsoft Windows Server 2008 for 32-bit Systems SP2
Microsoft Windows Server 2008 for Itanium-based Systems SP2
Microsoft Windows Server 2008 for x64-based Systems SP2
Microsoft Windows Server 2012

Affected Software

Microsoft Live Meeting 2007 Add-in
Microsoft Live Meeting 2007 Console
Microsoft Lync 2010 (32-bit)
Microsoft Lync 2010 (64-bit)
Microsoft Lync 2013 (32-bit) SP1
Microsoft Lync 2013 (64-bit) SP1
Microsoft Lync Basic 2013 (32-bit) SP1
Microsoft Lync Basic 2013 (64-bit) SP1
Microsoft Office 2007 SP3
Microsoft Office 2010 Service Pack 2 (32-bit editions)
Microsoft Office 2010 Service Pack 2 (64-bit editions)
Microsoft Office Web Apps 2010 SP2
Microsoft Office Word Viewer
Microsoft Skype for Business 2016 (32-bit)
Microsoft Skype for Business 2016 (64-bit)
Microsoft Skype for Business Basic 2016 (32-bit)
Microsoft Skype for Business Basic 2016 (64-bit)
Microsoft Windows 7 for 32-bit Systems SP1
Microsoft Windows 7 for x64-based Systems SP1
Microsoft Windows 8.1 for 32-bit Systems
Microsoft Windows Server 2008 R2 for Itanium-based Systems SP1
Microsoft Windows Server 2008 R2 for x64-based Systems SP1
Microsoft Windows Server 2008 for 32-bit Systems SP2
Microsoft Windows Server 2008 for Itanium-based Systems SP2
Microsoft Windows Server 2008 for x64-based Systems SP2
Microsoft Windows Server 2012