CVE-2017-8570
KEVHIGH 9.3EPSS 89.9%
Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Microsoft Office Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0243.
- CVSS v3.1
- 7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - CVSS v3.1
- 7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - CVSS v2.0
- 9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C - EPSS
- 89.89% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2022-02-25
- Published
- 2017-07-11
- Updated
- 2025-10-21
Proof-of-concept exploits (10)
- Drac0nids/CVE-2017-85702★ · 2019-01-03
- Farrahan/TestProject0★ · 2017-11-06
- MaxSecurity/Office-CVE-2017-85700★ · 2018-02-26
- SwordSheath/CVE-2017-85705★ · 2018-04-08
- erfze/CVE-2017-85701★ · 2020-08-22
- p2-98/Research-Exploit-Office1★ · 2020-04-19
- phamphuqui1998/Research-Exploit-Office1★ · 2020-04-19
- sasqwatch/CVE-2017-85700★ · 2019-05-07
- tezukanice/Office857094★ · 2017-08-13
- rxwx/CVE-2017-8570185★ · 2018-01-09