AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2017-2789

HIGH · CVSS 8.8 EPSS 2.34% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2017-02-24 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2017-2789
Severity
HIGH
CVSS
8.8
EPSS
2.34%
Office

Original NVD Description

When copying filedata into a buffer, JustSystems Ichitaro Office 2016 Trial will calculate two values to determine how much data to copy from the document. If both of these values are larger than the size of the buffer, the application will choose the smaller of the two and trust it to copy data from the file. This value is larger than the buffer size, which leads to a heap-based buffer overflow. This overflow corrupts an offset in the heap used in pointer arithmetic for writing data and can lead to code execution under the context of the application.