← Vulnerability feed

Vulnerability record · CVE-2017-8682 · published 13 September 2017

CVE-2017-8682: Microsoft Windows Win32k Embedded Font Handling Remote Code Execution

Microsoft · Office 2007

CVE-2017-8682 is an improper input validation flaw in how Microsoft Windows graphics handles embedded fonts, allowing remote code execution. It affects a wide range of Windows versions and Office products, including Word Viewer, Office 2007 and Office 2010. Because the flaw is in a core graphics component, successful exploitation can give an attacker full control of the affected system.

8.8 CVSS 3.0 High EPSS 50% · top 1.1% CWE-20 · Improper input validation
8.8CVSS 3.0 base score, v2 9.3
50%EPSS exploitation probability, 30 days
NoNot in CISA KEV
10Affected product versions listed by NVD
8References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Windows graphics on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, Windows Server 2016, Microsoft Office Word Viewer, Microsoft Office 2007 Service Pack 3 , and Microsoft Office 2010 Service Pack 2 allows an attacker to execute remote code by the way it handles embedded fonts, aka "Win32k Graphics Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-8683.

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

high priorityCVSS 8.8, high EPSS, and a public exploit make this a high-priority vulnerability for affected systems, despite not being in CISA KEV.

What it is

CVE-2017-8682 is an improper input validation flaw in how Microsoft Windows graphics handles embedded fonts, allowing remote code execution. It affects a wide range of Windows versions and Office products, including Word Viewer, Office 2007 and Office 2010. Because the flaw is in a core graphics component, successful exploitation can give an attacker full control of the affected system.

Impact

An attacker who successfully exploits this vulnerability can execute arbitrary code in the context of the current user. If the user has administrative privileges, the attacker could install programs, view, change, or delete data, or create new accounts with full user rights.

Attack surface

The vulnerability is reached over the network (AV:N) with no privileges required (PR:N), but requires user interaction (UI:R), such as opening a specially crafted document or visiting a malicious web page that renders embedded fonts. No authentication is needed to trigger the flaw.

Exploitation

The record is not listed in CISA KEV, but EPSS is high (0.49765, 98.8th percentile) and a public exploit exists on Exploit-DB (reference tagged Exploit). This indicates a realistic and elevated risk of exploitation.

What to do

  • Apply the Microsoft security update referenced in the vendor advisory (portal.msrc.microsoft.com) as soon as possible.
  • Disable or restrict the rendering of embedded fonts in affected applications where feasible.
  • Educate users not to open untrusted documents or click links from unknown sources.
  • Use application whitelisting and least-privilege principles to limit the impact of successful exploitation.
  • Consider network-level filtering or endpoint detection to block known exploit delivery vectors.

Detection

  • Monitor for processes spawning from Office applications or Word Viewer that exhibit unusual behavior, such as creating child processes or writing to system directories.
  • Look for crashes or exceptions in win32k.sys or related graphics components that correlate with document opening events.
  • Hunt for known exploit artifacts or shellcode patterns associated with the public Exploit-DB proof-of-concept (ID 42744).
  • Enable and review Windows Defender Exploit Guard or similar mitigations for anomalous font parsing behavior.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

10 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-8682 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-0708Microsoft Remote Desktop Services use-after-free remote code executionRemote Desktop Services (formerly Terminal Services) contains a use-after-free flaw that lets an unauthenticated attacker execute code by sending spe…KEVEPSS 100%analysed9.8CVE-2017-8543Windows Search memory handling flaw allows remote code executionWindows Search fails to properly handle objects in memory, allowing an unauthenticated remote attacker to execute code on affected Windows systems. T…KEVEPSS 74%analysed9.8CVE-2015-1635Microsoft HTTP.sys remote code execution via crafted HTTP requestsHTTP.sys in multiple Windows versions fails to properly handle crafted HTTP requests, allowing remote code execution. The flaw is reachable over the …KEVEPSS 100%analysed8.8CVE-2022-41128Windows Scripting Languages out-of-bounds write allows remote code executionCVE-2022-41128 is an out-of-bounds write (CWE-787) in Windows Scripting Languages that leads to remote code execution. Microsoft rates it 8.8 HIGH wi…KEVEPSS 25%analysed8.8CVE-2021-40444Microsoft MSHTML remote code execution via malicious Office documentCVE-2021-40444 is a remote code execution flaw in the MSHTML browser rendering engine on Microsoft Windows. An attacker can embed a malicious ActiveX…KEVEPSS 97%analysed8.8CVE-2020-1020Windows Adobe Type Manager Library font parsing out-of-bounds write RCEMicrosoft Windows Adobe Type Manager Library mishandles a specially crafted multi-master font in Adobe Type 1 PostScript format, causing an out-of-bo…KEVEPSS 65%analysed8.8CVE-2019-0903Windows GDI memory handling remote code executionWindows Graphics Device Interface (GDI) mishandles objects in memory, allowing remote code execution. The record gives no root-cause detail beyond th…KEVEPSS 22%analysed8.8CVE-2019-0541Microsoft MSHTML engine input validation flaw allows remote code executionThe MSHTML engine in Microsoft Office, Internet Explorer and related viewers fails to properly validate input, allowing remote code execution. Becaus…KEVEPSS 53%analysed

Source: NIST National Vulnerability Database (record CVE-2017-8682), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.