ZeroHour

CVE-2017-0261

KEVmass

Use-After-Free RCE in Microsoft Office 2010/2013/2016

CISA: Microsoft Office Use-After-Free Vulnerability

CVSS 3.1
7.8 high
EPSS
78%p100
Published
()
KEV added
AI analysis

CVE-2017-0261 is a use-after-free (CWE-416) remote code execution flaw in Microsoft Office 2010 SP2, 2013 SP1, and 2016, caused by improper handling of objects in memory. It is triggered by convincing a user to open a malicious document or email attachment, which corrupts memory and lets the attacker run arbitrary code with the victim's privileges (high impact on confidentiality, integrity, and availability). Any user of the affected Office editions is exposed, and because the attack requires user interaction via a crafted file, email-borne targeting is the realistic attack path. The flaw was patched in Microsoft's May 2017 Patch Tuesday releases after being exploited as a zero day, with public reporting linking active exploitation to Russian APT groups. It is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03), and its EPSS score of 78.1% (100th percentile) reflects a very high likelihood of exploitation.

What to do: Apply Microsoft's May 2017 Patch Tuesday security updates to all installations of Office 2010 SP2, 2013 SP1, and 2016, following the vendor's instructions as required by the CISA KEV listing. Until patched, warn users against opening unsolicited or untrusted Office attachments and consider email filtering to block risky file types. Verify fleet compliance against the KEV required action (apply updates per vendor instructions) and prioritize endpoints of targeted or high-value users.

Affected
Microsoft Office 2010Service Pack 2
Microsoft Office 2013Service Pack 1
Microsoft Office 2016all versions prior to the May 2017 security updates
Estimated exposure
masstens to hundreds of millions of users (Office's global install base across the affected editions) — Microsoft Office is deployed on effectively hundreds of millions of enterprise and consumer PCs, so the affected 2010/2013/2016 editions at the time of disclosure represented a mass-scale install base; precise counts are unknown.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0262 and CVE-2017-0281.

CISA Known Exploited Vulnerability
Affected
Microsoft Office
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
office
Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent

Unit 42 details Patchwork APT campaigns against the Indian subcontinent using EPS exploits and an updated BADNEWS backdoor targeting Pakistani military and nuclear interests.

Unit 42 observed the Patchwork group (also known as Dropping Elephant and Monsoon) conducting campaigns against targets in the Indian subcontinent using weaponized documents that exploit CVE-2015-2545 and CVE-2017-0261. The documents deliver an updated BADNEWS backdoor that grants attackers full control of victim machines, using dead drop resolvers on legitimate third-party websites for C2 and HTTP for communications. Lures referenced Pakistan Army promotions, the Pakistan Atomic Energy Commission and the Ministry of the Interior, and in late January 2018 the group shifted from CVE-2017-0261 to the older CVE-2015-2545.

Palo Alto Unit 42 · 29d agoThreat actor in the wildCVE-2015-2545CVE-2017-0261