Vulnerability record · CVE-2017-0108 · published 17 March 2017
CVE-2017-0108: Windows Graphics Component buffer overflow allows remote code execution
Microsoft · Live Meeting
The Windows Graphics Component contains a memory buffer overflow (CWE-119) that can be triggered by a crafted website, leading to arbitrary code execution. It affects a wide range of Microsoft products including Office 2007/2010, Word Viewer, Skype for Business 2016, Lync 2013/2010, Live Meeting 2007, Silverlight 5, and several Windows versions. Because the flaw is in a core graphics component, it is reachable from many applications and poses a broad risk.
Description
The Windows Graphics Component in Microsoft Office 2007 SP3; 2010 SP2; and Word Viewer; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Live Meeting 2007; Silverlight 5; Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; and Windows 7 SP1 allows remote attackers to execute arbitrary code via a crafted web site, aka "Graphics Component Remote Code Execution Vulnerability." This vulnerability is different from that described in CVE-2017-0014.
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityAlthough not in KEV, the high EPSS score and public exploit availability combined with a wide attack surface make this a high-priority vulnerability for patching.
What it is
The Windows Graphics Component contains a memory buffer overflow (CWE-119) that can be triggered by a crafted website, leading to arbitrary code execution. It affects a wide range of Microsoft products including Office 2007/2010, Word Viewer, Skype for Business 2016, Lync 2013/2010, Live Meeting 2007, Silverlight 5, and several Windows versions. Because the flaw is in a core graphics component, it is reachable from many applications and poses a broad risk.
Impact
An attacker who successfully exploits this vulnerability can execute arbitrary code in the context of the current user. If the user has administrative privileges, the attacker could take full control of the affected system.
Attack surface
The vulnerability is reached via a crafted website, requiring the user to visit the site or open a malicious document. The CVSS vector indicates local access (AV:L) with user interaction (UI:R) and no privileges required (PR:N), meaning the attacker must convince a user to open a specially crafted file or view a malicious web page.
Exploitation
The CVE is not listed in CISA KEV, but EPSS indicates a high probability of exploitation (0.5047, 98.8th percentile) and a public exploit exists on Exploit-DB (41647).
What to do
- Apply the Microsoft security update referenced in the vendor advisory (portal.msrc.microsoft.com).
- Upgrade or remove unsupported products such as Office 2007, Word Viewer, Live Meeting 2007, and Silverlight 5 where feasible.
- Enforce the principle of least privilege so users do not operate with administrative rights.
- Use email and web filtering to block malicious documents and websites that could trigger the flaw.
- Enable exploit protection features such as DEP and ASLR, and consider disabling unnecessary graphics-related components.
Detection
- Monitor for unusual process creation or code execution originating from Office, Lync, Skype for Business, or Silverlight processes.
- Look for crashes or exceptions in graphics-related DLLs (e.g., gdi32.dll, win32k.sys) that may indicate exploitation attempts.
- Review web proxy and email logs for access to known malicious sites or delivery of crafted documents targeting these products.
- Use endpoint detection to flag suspicious child processes spawned by affected applications.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/96722 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1038002 | |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0108 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/41647/ | |
| http://www.securityfocus.com/bid/96722 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1038002 | |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0108 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/41647/ |
Track CVE-2017-0108 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-0108), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.