CVE-2017-0292

high Microsoft
CVSS v3 Base Score
7.8
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
28.4%
Exploitation probability in 30 days
Top 3% most likely to be exploited
Attack Characteristics
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Confidentiality
High
Integrity
High
Availability
High
Published: June 15, 2017 (3256 days ago)
Last Modified: May 13, 2026
Vendor: Microsoft
Source: NVD

Description

Windows PDF in Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows remote code execution if a user opens a specially crafted PDF file, aka "Windows PDF Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0291.

CWE

NVD-CWE-noinfo

Affected Products

microsoft wordmicrosoft windows 10microsoft windows 8.1microsoft windows rt 8.1microsoft windows server 2012microsoft windows server 2016

References