CVE-2017-11826
KEV PoC ×2massMemory Corruption RCE in Microsoft Office, Word, SharePoint and Office Web Apps
CISA: Microsoft Office Remote Code Execution Vulnerability
Affected versions of Microsoft Office and related server products fail to properly handle objects in memory (CWE-119 memory corruption), allowing remote code execution. The flaw is triggered when a user opens a specially crafted document, for example a malicious Word file delivered by email, with an affected version of Word, Word Viewer, the Office Compatibility Pack, Office 2010, or an affected SharePoint / Office Web Apps / Office Online Server component; the CVSS vector (AV:L, UI:R) reflects this user-interaction requirement. A successful attacker runs arbitrary code in the context of the logged-in user, with high impact on confidentiality, integrity and availability (CVSS 3.1 base 7.8, high). Anyone running Word 2007/2010/2013/2016, Office 2010, Word Viewer, the Office Compatibility Pack, SharePoint Enterprise Server 2010 or SharePoint Server 2010 (including Word Automation Services), Office Web Apps Server 2010 and 2013, Office Web Applications, or Office Online Server is affected. The bug was addressed as an Office zero-day in Microsoft's October 2017 Patch Tuesday release, is listed in the CISA KEV catalog (added 2022-03-03, indicating exploitation in the wild; ransomware use unknown), and EPSS assigns an 81.3% probability of exploitation within 30 days (100th percentile).
What to do: Apply Microsoft's October 2017 Patch Tuesday security updates to all affected components, including the frequently missed Word Viewer and Office Compatibility Pack, across endpoints, SharePoint 2010 servers, and Office Web Apps/Office Online Server deployments (KEV required action: apply updates per vendor instructions). Until patched, treat unsolicited Word documents and attachments as untrusted and verify users' installed Office builds. Prioritize remediation given confirmed in-the-wild exploitation.
| Microsoft Office 2010 | 2010 |
| Microsoft Word | 2007, 2010, 2013, 2016 |
| Microsoft Word Viewer | — |
| Microsoft Office Compatibility Pack | — |
| Microsoft SharePoint Enterprise Server | 2010 |
| Microsoft SharePoint Server | 2010 |
| Microsoft Word Automation Services (SharePoint) | — |
| Microsoft Office Web Apps (Web Applications) | — |
| Microsoft Office Web Apps Server | 2010, 2013 |
| Microsoft Office Online Server | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word Viewer, Word 2007, 2010, 2013 and 2016, Word Automation Services, and Office Online Server allow remote code execution when the software fails to properly handle objects in memory.
- Affected
- Microsoft Office
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- office compatibility pack, office online server, office web apps server, office word viewer, sharepoint enterprise server, sharepoint server, word
- Weakness
- CWE-119
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H