CVE-2017-11877

Microsoft Excel 2007 Service Pack 3, Microsoft Excel 2010 Service Pack 2, Microsoft Excel 2013 Service Pack 1, Microsoft Excel 2013 RT Service Pack 1, Microsoft Excel 2016, Microsoft Office Compatibility Pack Service Pack 3, Microsoft Excel Viewer 2007 Service Pack 3, and Microsoft Excel 2016 for Mac allow a security feature bypass by not enforcing macro settings on an Excel document, aka "Microsoft Excel Security Feature Bypass Vulnerability".
References
Link Resource
http://www.securityfocus.com/bid/101747 Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1039783 Third Party Advisory VDB Entry
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11877 Issue Tracking Patch Vendor Advisory
http://www.securityfocus.com/bid/101747 Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1039783 Third Party Advisory VDB Entry
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11877 Issue Tracking Patch Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:microsoft:excel:2007:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:excel:2010:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:excel:2013:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:excel:2013:sp1:*:*:*:*:*:*
cpe:2.3:a:microsoft:excel:2016:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:excel:2016:*:*:*:*:mac_os_x:*:*
cpe:2.3:a:microsoft:excel_viewer:2007:sp3:*:*:*:*:*:*
cpe:2.3:a:microsoft:office_compatibility_pack:-:sp3:*:*:*:*:*:*

History

21 Nov 2024, 03:08

Type Values Removed Values Added
References () http://www.securityfocus.com/bid/101747 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/101747 - Third Party Advisory, VDB Entry
References () http://www.securitytracker.com/id/1039783 - Third Party Advisory, VDB Entry () http://www.securitytracker.com/id/1039783 - Third Party Advisory, VDB Entry
References () https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11877 - Issue Tracking, Patch, Vendor Advisory () https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11877 - Issue Tracking, Patch, Vendor Advisory

Information

Published : 2017-11-15 03:29

Updated : 2025-04-20 01:37


NVD link : CVE-2017-11877

Mitre link : CVE-2017-11877

CVE.ORG link : CVE-2017-11877


JSON object : View

Products Affected

microsoft

  • excel_viewer
  • excel
  • office_compatibility_pack