ZeroHour

CVE-2017-0262

KEVmass

Memory Corruption RCE in Microsoft Office 2010, 2013, and 2016

CISA: Microsoft Office Remote Code Execution Vulnerability

CVSS 3.1
7.8 high
EPSS
81%p100
Published
()
KEV added
AI analysis

Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 fail to properly handle objects in memory, creating a remote code execution condition when the software processes a specially crafted file. Triggering the flaw requires user interaction - the CVSS vector (AV:L, UI:R) indicates an attacker must get a user to open a malicious document, typically via a phishing email or similar file-delivery channel. Successful exploitation runs arbitrary code in the context of the current user, exposing the confidentiality, integrity, and availability of everything that account can access on the endpoint (CVSS 3.1: 7.8, High). Any organization running the affected Office versions is affected; the flaw was one of several Office zero-days fixed in Microsoft's May 2017 Patch Tuesday (distinct from CVE-2017-0261 and CVE-2017-0281) and was reportedly exploited by Russian APT actors (APT28/Sofacy) around that time. Exploitation is confirmed: CISA added it to the Known Exploited Vulnerabilities catalog on 2022-02-10, and EPSS currently rates the 30-day exploitation probability at 81% (100th percentile), so unpatched endpoints should be treated as actively targeted.

What to do: Apply Microsoft's May 2017 security updates for Office 2010 SP2, Office 2013 SP1, and Office 2016, per the CISA KEV required action, and verify through asset inventory that no endpoint is running an unpatched Office build. Because exploitation requires user interaction with a crafted file, harden email and attachment handling (block or detonate Office files from untrusted sources) and brief users on unsolicited documents. Office 2010 and 2013 have since reached end of support, so migrate any remaining deployments to a currently supported Office release.

Affected
Microsoft Office 2010Service Pack 2
Microsoft Office 2013Service Pack 1
Microsoft Office 2016
Estimated exposure
masstens to hundreds of millions of endpoints (Office 2010 SP2/2013 SP1/2016 dominated desktop deployments at disclosure; current unpatched count unknown) — Microsoft Office historically ran on more than a billion devices worldwide and the 2010/2013/2016 releases made up the bulk of enterprise desktop installs through 2017-2020, so plausibly affected installations number well above 1 million…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0261 and CVE-2017-0281.

CISA Known Exploited Vulnerability
Affected
Microsoft Office
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
office
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news