CVE-2017-11939
CVE-2017-11939
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 6.3%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
12 Dec 2017Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Microsoft Office 2016 Click-to-Run (C2R) allows an information disclosure vulnerability due to the way Microsoft Office enforces DRM copy/paste permissions, aka "Microsoft Office Information Disclosure Vulnerability".
Affected products
Microsoft Corporation · Microsoft OfficeWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →