vendor:
Microsoft Office
by:
Voulnet
7,8
CVSS
HIGH
CVE-2017-8759
20
CWE
Product Name: Microsoft Office
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: CVE-2017-8759
CPE: N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2017
Running CVE-2017-8759 exploit sample
The exploit involves a Word macro running in the Doc1.doc file which downloads a badly formatted txt file over wsdl, which triggers the WSDL parser log. Then the parsing log results in running mshta.exe which in turn runs a powershell commands that runs mspaint.exe
Mitigation:
Disable macros in Microsoft Office, use a web application firewall, and ensure that all web applications are patched and up to date.