Vulnerability record · CVE-2017-8682 · published 13 September 2017
CVE-2017-8682: Microsoft Windows Win32k Embedded Font Handling Remote Code Execution
Microsoft · Office 2007
CVE-2017-8682 is an improper input validation flaw in how Microsoft Windows graphics handles embedded fonts, allowing remote code execution. It affects a wide range of Windows versions and Office products, including Word Viewer, Office 2007 and Office 2010. Because the flaw is in a core graphics component, successful exploitation can give an attacker full control of the affected system.
Description
Windows graphics on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, Windows Server 2016, Microsoft Office Word Viewer, Microsoft Office 2007 Service Pack 3 , and Microsoft Office 2010 Service Pack 2 allows an attacker to execute remote code by the way it handles embedded fonts, aka "Win32k Graphics Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-8683.
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8, high EPSS, and a public exploit make this a high-priority vulnerability for affected systems, despite not being in CISA KEV.
What it is
CVE-2017-8682 is an improper input validation flaw in how Microsoft Windows graphics handles embedded fonts, allowing remote code execution. It affects a wide range of Windows versions and Office products, including Word Viewer, Office 2007 and Office 2010. Because the flaw is in a core graphics component, successful exploitation can give an attacker full control of the affected system.
Impact
An attacker who successfully exploits this vulnerability can execute arbitrary code in the context of the current user. If the user has administrative privileges, the attacker could install programs, view, change, or delete data, or create new accounts with full user rights.
Attack surface
The vulnerability is reached over the network (AV:N) with no privileges required (PR:N), but requires user interaction (UI:R), such as opening a specially crafted document or visiting a malicious web page that renders embedded fonts. No authentication is needed to trigger the flaw.
Exploitation
The record is not listed in CISA KEV, but EPSS is high (0.49765, 98.8th percentile) and a public exploit exists on Exploit-DB (reference tagged Exploit). This indicates a realistic and elevated risk of exploitation.
What to do
- Apply the Microsoft security update referenced in the vendor advisory (portal.msrc.microsoft.com) as soon as possible.
- Disable or restrict the rendering of embedded fonts in affected applications where feasible.
- Educate users not to open untrusted documents or click links from unknown sources.
- Use application whitelisting and least-privilege principles to limit the impact of successful exploitation.
- Consider network-level filtering or endpoint detection to block known exploit delivery vectors.
Detection
- Monitor for processes spawning from Office applications or Word Viewer that exhibit unusual behavior, such as creating child processes or writing to system directories.
- Look for crashes or exceptions in win32k.sys or related graphics components that correlate with document opening events.
- Hunt for known exploit artifacts or shellcode patterns associated with the public Exploit-DB proof-of-concept (ID 42744).
- Enable and review Windows Defender Exploit Guard or similar mitigations for anomalous font parsing behavior.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
10 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/100772 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039352 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8682 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/42744/ | ExploitThird Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/100772 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039352 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8682 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/42744/ | ExploitThird Party AdvisoryVDB Entry |
Track CVE-2017-8682 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-8682), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.