E17-0bfb8
CVSS:
7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
False Positive:
f
Variants:
64
Year:
2017
Description
This strike exploits a vulnerability in the way Microsoft Office and Wordpad handles linked URL Moniker OLE objects.
The vulnerability gives the attacker remote code execution through MSHTA.exe by forcing the response headers to be of type "application/hta."
An attacker may exploit this vulnerability by enticing a user to open a specifically crafted RTF document via email or other methods.
CVE
References
https://github.com/bhdresh/CVE-2017-0199