← Vulnerability feed

Vulnerability record · CVE-2017-0108 · published 17 March 2017

CVE-2017-0108: Windows Graphics Component buffer overflow allows remote code execution

Microsoft · Live Meeting

The Windows Graphics Component contains a memory buffer overflow (CWE-119) that can be triggered by a crafted website, leading to arbitrary code execution. It affects a wide range of Microsoft products including Office 2007/2010, Word Viewer, Skype for Business 2016, Lync 2013/2010, Live Meeting 2007, Silverlight 5, and several Windows versions. Because the flaw is in a core graphics component, it is reachable from many applications and poses a broad risk.

7.8 CVSS 3.0 High EPSS 50% · top 1.1% CWE-119 · Memory buffer overflow
7.8CVSS 3.0 base score, v2 9.3
50%EPSS exploitation probability, 30 days
NoNot in CISA KEV
9Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

The Windows Graphics Component in Microsoft Office 2007 SP3; 2010 SP2; and Word Viewer; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Live Meeting 2007; Silverlight 5; Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; and Windows 7 SP1 allows remote attackers to execute arbitrary code via a crafted web site, aka "Graphics Component Remote Code Execution Vulnerability." This vulnerability is different from that described in CVE-2017-0014.

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

high priorityAlthough not in KEV, the high EPSS score and public exploit availability combined with a wide attack surface make this a high-priority vulnerability for patching.

What it is

The Windows Graphics Component contains a memory buffer overflow (CWE-119) that can be triggered by a crafted website, leading to arbitrary code execution. It affects a wide range of Microsoft products including Office 2007/2010, Word Viewer, Skype for Business 2016, Lync 2013/2010, Live Meeting 2007, Silverlight 5, and several Windows versions. Because the flaw is in a core graphics component, it is reachable from many applications and poses a broad risk.

Impact

An attacker who successfully exploits this vulnerability can execute arbitrary code in the context of the current user. If the user has administrative privileges, the attacker could take full control of the affected system.

Attack surface

The vulnerability is reached via a crafted website, requiring the user to visit the site or open a malicious document. The CVSS vector indicates local access (AV:L) with user interaction (UI:R) and no privileges required (PR:N), meaning the attacker must convince a user to open a specially crafted file or view a malicious web page.

Exploitation

The CVE is not listed in CISA KEV, but EPSS indicates a high probability of exploitation (0.5047, 98.8th percentile) and a public exploit exists on Exploit-DB (41647).

What to do

  • Apply the Microsoft security update referenced in the vendor advisory (portal.msrc.microsoft.com).
  • Upgrade or remove unsupported products such as Office 2007, Word Viewer, Live Meeting 2007, and Silverlight 5 where feasible.
  • Enforce the principle of least privilege so users do not operate with administrative rights.
  • Use email and web filtering to block malicious documents and websites that could trigger the flaw.
  • Enable exploit protection features such as DEP and ASLR, and consider disabling unnecessary graphics-related components.

Detection

  • Monitor for unusual process creation or code execution originating from Office, Lync, Skype for Business, or Silverlight processes.
  • Look for crashes or exceptions in graphics-related DLLs (e.g., gdi32.dll, win32k.sys) that may indicate exploitation attempts.
  • Review web proxy and email logs for access to known malicious sites or delivery of crafted documents targeting these products.
  • Use endpoint detection to flag suspicious child processes spawned by affected applications.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-0108 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-23397Microsoft Outlook improper input validation privilege escalationCVE-2023-23397 is a critical elevation of privilege flaw in Microsoft Outlook caused by improper input validation and an authentication bypass by cap…KEVEPSS 97%analysed8.8CVE-2023-35311Microsoft Outlook security feature bypass via TOCTOU race conditionCVE-2023-35311 is a security feature bypass in Microsoft Outlook caused by a time-of-check time-of-use (TOCTOU) race condition (CWE-367). It affects …KEVEPSS 16%analysed8.8CVE-2019-1297Microsoft Excel memory handling flaw allows remote code executionCVE-2019-1297 is a remote code execution vulnerability in Microsoft Excel caused by improper handling of objects in memory. An attacker who convinces…KEVEPSS 22%analysed8.8CVE-2019-0541Microsoft MSHTML engine input validation flaw allows remote code executionThe MSHTML engine in Microsoft Office, Internet Explorer and related viewers fails to properly validate input, allowing remote code execution. Becaus…KEVEPSS 53%analysed8.8CVE-2018-0798Microsoft Office Equation Editor memory corruption RCEEquation Editor in Microsoft Office 2007 through 2016 mishandles objects in memory, producing an out-of-bounds write (CWE-787) that can be turned int…KEVEPSS 95%analysed8.8CVE-2016-0034Microsoft Silverlight negative offset decoding flaw allows remote code executionMicrosoft Silverlight 5 before 5.1.41212.0 mishandles negative offsets during decoding, corrupting object headers. A remote attacker can exploit this…KEVEPSS 69%analysed8.8CVE-2015-2424Microsoft Office memory corruption via crafted documentCVE-2015-2424 is an out-of-bounds write (CWE-787) in Microsoft PowerPoint and Word that is triggered when a crafted Office document is opened. A remo…KEVEPSS 40%analysed8.8CVE-2015-1770Microsoft Office uninitialized memory use allows remote code executionMicrosoft Office 2013 SP1 and 2013 RT SP1 mishandle uninitialized memory when parsing a crafted Office document, which can lead to arbitrary code exe…KEVEPSS 35%analysed

Source: NIST National Vulnerability Database (record CVE-2017-0108), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.