CVE-2017-0262
KEVmassMemory Corruption RCE in Microsoft Office 2010, 2013, and 2016
CISA: Microsoft Office Remote Code Execution Vulnerability
Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 fail to properly handle objects in memory, creating a remote code execution condition when the software processes a specially crafted file. Triggering the flaw requires user interaction - the CVSS vector (AV:L, UI:R) indicates an attacker must get a user to open a malicious document, typically via a phishing email or similar file-delivery channel. Successful exploitation runs arbitrary code in the context of the current user, exposing the confidentiality, integrity, and availability of everything that account can access on the endpoint (CVSS 3.1: 7.8, High). Any organization running the affected Office versions is affected; the flaw was one of several Office zero-days fixed in Microsoft's May 2017 Patch Tuesday (distinct from CVE-2017-0261 and CVE-2017-0281) and was reportedly exploited by Russian APT actors (APT28/Sofacy) around that time. Exploitation is confirmed: CISA added it to the Known Exploited Vulnerabilities catalog on 2022-02-10, and EPSS currently rates the 30-day exploitation probability at 81% (100th percentile), so unpatched endpoints should be treated as actively targeted.
What to do: Apply Microsoft's May 2017 security updates for Office 2010 SP2, Office 2013 SP1, and Office 2016, per the CISA KEV required action, and verify through asset inventory that no endpoint is running an unpatched Office build. Because exploitation requires user interaction with a crafted file, harden email and attachment handling (block or detonate Office files from untrusted sources) and brief users on unsolicited documents. Office 2010 and 2013 have since reached end of support, so migrate any remaining deployments to a currently supported Office release.
| Microsoft Office 2010 | Service Pack 2 |
| Microsoft Office 2013 | Service Pack 1 |
| Microsoft Office 2016 | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0261 and CVE-2017-0281.
- Affected
- Microsoft Office
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- office
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H