Vulnerability Name: | CVE-2017-11877 (CCN-134256) |
Assigned: | 2017-11-14 |
Published: | 2017-11-14 |
Updated: | 2019-10-03 |
Summary: | Microsoft Excel 2007 Service Pack 3, Microsoft Excel 2010 Service Pack 2, Microsoft Excel 2013 Service Pack 1, Microsoft Excel 2013 RT Service Pack 1, Microsoft Excel 2016, Microsoft Office Compatibility Pack Service Pack 3, Microsoft Excel Viewer 2007 Service Pack 3, and Microsoft Excel 2016 for Mac allow a security feature bypass by not enforcing macro settings on an Excel document, aka "Microsoft Excel Security Feature Bypass Vulnerability".
|
CVSS v3 Severity: | 5.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N) 4.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C)Exploitability Metrics: | Attack Vector (AV): Local Attack Complexity (AC): Low Privileges Required (PR): None User Interaction (UI): Required | Scope: | Scope (S): Unchanged
| Impact Metrics: | Confidentiality (C): None Integrity (I): High Availibility (A): None | 4.4 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N) 3.9 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C)Exploitability Metrics: | Attack Vector (AV): Local Attack Complexity (AC): Low Privileges Required (PR): None User Interaction (UI): Required | Scope: | Scope (S): Unchanged
| Impact Metrics: | Confidentiality (C): Low Integrity (I): Low Availibility (A): None |
|
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Medium Authentication (Au): None | Impact Metrics: | Confidentiality (C): None Integrity (I): Partial Availibility (A): None | 3.2 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:P/I:P/A:N)Exploitability Metrics: | Access Vector (AV): Local Access Complexity (AC): Low Athentication (Au): Single_Instance
| Impact Metrics: | Confidentiality (C): Partial Integrity (I): Partial Availibility (A): None |
|
Vulnerability Type: | CWE-noinfo
|
Vulnerability Consequences: | Bypass Security |
References: | Source: MITRE Type: CNA CVE-2017-11877
Source: BID Type: Third Party Advisory, VDB Entry 101747
Source: CCN Type: BID-101747 Microsoft Excel CVE-2017-11877 Security Bypass Vulnerability
Source: SECTRACK Type: Third Party Advisory, VDB Entry 1039783
Source: XF Type: UNKNOWN ms-excel-cve201711877-sec-bypass(134256)
Source: CCN Type: Microsoft Security TechCenter - November 2017 Microsoft Excel Security Feature Bypass Vulnerability
Source: CONFIRM Type: Issue Tracking, Patch, Vendor Advisory https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11877
|
Vulnerable Configuration: | Configuration 1: cpe:/a:microsoft:excel:2013:sp1:*:*:*:*:*:*OR cpe:/a:microsoft:excel:2016:*:*:*:*:*:*:*OR cpe:/a:microsoft:excel:2016:*:*:*:*:mac_os_x:*:*OR cpe:/a:microsoft:excel_2007:-:sp3:*:*:*:*:*:*OR cpe:/a:microsoft:excel_2010:*:sp2:*:*:*:*:*:*OR cpe:/a:microsoft:excel_2013_rt:-:sp1:*:*:*:*:*:*OR cpe:/a:microsoft:excel_viewer:2007:sp3:*:*:*:*:*:*OR cpe:/a:microsoft:office_compatibility_pack:-:sp3:*:*:*:*:*:* Configuration CCN 1: cpe:/a:microsoft:excel_viewer:*:*:*:*:*:*:*:*OR cpe:/a:microsoft:excel:2007:sp3:*:*:*:*:*:*OR cpe:/a:microsoft:office_compatibility_pack:*:sp3:*:*:*:*:*:*OR cpe:/a:microsoft:excel:2010:sp2:*:*:*:*:x64:*OR cpe:/a:microsoft:excel:2010:sp2:*:*:*:*:x32:*OR cpe:/a:microsoft:excel:2013:sp1:*:*:*:*:x32:*OR cpe:/a:microsoft:excel:2013:sp1:*:*:*:*:x64:*OR cpe:/a:microsoft:excel:2013:sp1:*:*:rt:*:*:*OR cpe:/a:microsoft:excel:2016:*:*:*:*:*:x32:*OR cpe:/a:microsoft:excel:2016:*:*:*:*:*:x64:*
Denotes that component is vulnerable |
BACK |