ZeroHour

CVE-2017-11826

KEV PoC ×2mass

Memory Corruption RCE in Microsoft Office, Word, SharePoint and Office Web Apps

CISA: Microsoft Office Remote Code Execution Vulnerability

CVSS 3.1
7.8 high
EPSS
81%p100
Published
()
KEV added
AI analysis

Affected versions of Microsoft Office and related server products fail to properly handle objects in memory (CWE-119 memory corruption), allowing remote code execution. The flaw is triggered when a user opens a specially crafted document, for example a malicious Word file delivered by email, with an affected version of Word, Word Viewer, the Office Compatibility Pack, Office 2010, or an affected SharePoint / Office Web Apps / Office Online Server component; the CVSS vector (AV:L, UI:R) reflects this user-interaction requirement. A successful attacker runs arbitrary code in the context of the logged-in user, with high impact on confidentiality, integrity and availability (CVSS 3.1 base 7.8, high). Anyone running Word 2007/2010/2013/2016, Office 2010, Word Viewer, the Office Compatibility Pack, SharePoint Enterprise Server 2010 or SharePoint Server 2010 (including Word Automation Services), Office Web Apps Server 2010 and 2013, Office Web Applications, or Office Online Server is affected. The bug was addressed as an Office zero-day in Microsoft's October 2017 Patch Tuesday release, is listed in the CISA KEV catalog (added 2022-03-03, indicating exploitation in the wild; ransomware use unknown), and EPSS assigns an 81.3% probability of exploitation within 30 days (100th percentile).

What to do: Apply Microsoft's October 2017 Patch Tuesday security updates to all affected components, including the frequently missed Word Viewer and Office Compatibility Pack, across endpoints, SharePoint 2010 servers, and Office Web Apps/Office Online Server deployments (KEV required action: apply updates per vendor instructions). Until patched, treat unsolicited Word documents and attachments as untrusted and verify users' installed Office builds. Prioritize remediation given confirmed in-the-wild exploitation.

Affected
Microsoft Office 20102010
Microsoft Word2007, 2010, 2013, 2016
Microsoft Word Viewer
Microsoft Office Compatibility Pack
Microsoft SharePoint Enterprise Server2010
Microsoft SharePoint Server2010
Microsoft Word Automation Services (SharePoint)
Microsoft Office Web Apps (Web Applications)
Microsoft Office Web Apps Server2010, 2013
Microsoft Office Online Server
Estimated exposure
masshundreds of millions of desktop Office/Word installations (Microsoft's Office installed base exceeded 1 billion users when the flaw was disclosed), plus tens… — Order-of-magnitude estimate: Microsoft publicly reported over 1.2 billion Office users around the 2017 disclosure and Office 2010 was then the most widely deployed version, while SharePoint 2010 and Office Web Apps/Online Server are widely…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word Viewer, Word 2007, 2010, 2013 and 2016, Word Automation Services, and Office Online Server allow remote code execution when the software fails to properly handle objects in memory.

CISA Known Exploited Vulnerability
Affected
Microsoft Office
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
office compatibility pack, office online server, office web apps server, office word viewer, sharepoint enterprise server, sharepoint server, word
Weakness
CWE-119
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news