Microsoft Office OLE Composite Moniker Exploit

Strike ID:
E17-0hvu1
CVSS:
7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
False Positive:
f
Variants:
1
Year:
2017

Description

This strike exploits a remote code execution vulnerability in Microsoft Office. The vulnerability can be triggered by crafting an office document that leverages Composite Monikers. An attacker could exploit this vulnerability to execute code in the context of the current user.

CVE

References

Bid