ID

VAR-201711-1055


CVE

CVE-2017-7132


TITLE

Apple macOS of Quick Look Vulnerability in arbitrary code execution in components

Trust: 0.8

sources: JVNDB: JVNDB-2017-010362

DESCRIPTION

An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Quick Look" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory consumption) via a crafted Office document. Apple macOS High Sierra is a set of dedicated operating systems developed by Apple (Apple) for Mac computers. A security vulnerability exists in the Quick Look component of Apple macOS High Sierra prior to 10.13.1

Trust: 1.71

sources: NVD: CVE-2017-7132 // JVNDB: JVNDB-2017-010362 // VULHUB: VHN-115335

AFFECTED PRODUCTS

vendor:applemodel:mac os xscope:lteversion:10.13.0

Trust: 1.0

vendor:applemodel:mac os xscope:eqversion:10.11.6

Trust: 0.8

vendor:applemodel:mac os xscope:eqversion:10.12.6

Trust: 0.8

vendor:applemodel:mac os xscope:eqversion:10.13.0

Trust: 0.6

sources: JVNDB: JVNDB-2017-010362 // CNNVD: CNNVD-201703-981 // NVD: CVE-2017-7132

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2017-7132
value: HIGH

Trust: 1.0

NVD: CVE-2017-7132
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201703-981
value: MEDIUM

Trust: 0.6

VULHUB: VHN-115335
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2017-7132
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-115335
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2017-7132
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-115335 // JVNDB: JVNDB-2017-010362 // CNNVD: CNNVD-201703-981 // NVD: CVE-2017-7132

PROBLEMTYPE DATA

problemtype:CWE-400

Trust: 1.9

sources: VULHUB: VHN-115335 // JVNDB: JVNDB-2017-010362 // NVD: CVE-2017-7132

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201703-981

TYPE

lack of information

Trust: 0.6

sources: CNNVD: CNNVD-201703-981

CONFIGURATIONS

sources: JVNDB: JVNDB-2017-010362

PATCH

title:Apple security updatesurl:https://support.apple.com/en-us/HT201222

Trust: 0.8

title:HT208221url:https://support.apple.com/en-us/HT208221

Trust: 0.8

title:HT208221url:https://support.apple.com/ja-jp/HT208221

Trust: 0.8

sources: JVNDB: JVNDB-2017-010362

EXTERNAL IDS

db:NVDid:CVE-2017-7132

Trust: 2.5

db:SECTRACKid:1039710

Trust: 1.1

db:JVNid:JVNVU99000953

Trust: 0.8

db:JVNDBid:JVNDB-2017-010362

Trust: 0.8

db:CNNVDid:CNNVD-201703-981

Trust: 0.7

db:VULHUBid:VHN-115335

Trust: 0.1

sources: VULHUB: VHN-115335 // JVNDB: JVNDB-2017-010362 // CNNVD: CNNVD-201703-981 // NVD: CVE-2017-7132

REFERENCES

url:https://support.apple.com/ht208221

Trust: 1.7

url:http://www.securitytracker.com/id/1039710

Trust: 1.1

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2017-7132

Trust: 0.8

url:http://jvn.jp/vu/jvnvu99000953/index.html

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2017-7132

Trust: 0.8

sources: VULHUB: VHN-115335 // JVNDB: JVNDB-2017-010362 // CNNVD: CNNVD-201703-981 // NVD: CVE-2017-7132

SOURCES

db:VULHUBid:VHN-115335
db:JVNDBid:JVNDB-2017-010362
db:CNNVDid:CNNVD-201703-981
db:NVDid:CVE-2017-7132

LAST UPDATE DATE

2025-04-20T22:41:56.433000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-115335date:2017-11-27T00:00:00
db:JVNDBid:JVNDB-2017-010362date:2017-12-13T00:00:00
db:CNNVDid:CNNVD-201703-981date:2017-11-14T00:00:00
db:NVDid:CVE-2017-7132date:2025-04-20T01:37:25.860

SOURCES RELEASE DATE

db:VULHUBid:VHN-115335date:2017-11-13T00:00:00
db:JVNDBid:JVNDB-2017-010362date:2017-12-13T00:00:00
db:CNNVDid:CNNVD-201703-981date:2017-03-23T00:00:00
db:NVDid:CVE-2017-7132date:2017-11-13T03:29:02.553