Vulnerability record · CVE-2017-0199 · published 12 April 2017
CVE-2017-0199: Microsoft Office and WordPad remote code execution via crafted document
Microsoft · Office
CVE-2017-0199 is a remote code execution flaw in Microsoft Office and WordPad that is triggered when a user opens a specially crafted document. The record does not specify the exact underlying coding error, and NVD classifies the weakness as insufficient information. It matters because the flaw is in widely deployed Office and Windows components and has been exploited in real attacks.
Description
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, Windows 8.1 allow remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office/WordPad Remote Code Execution Vulnerability w/Windows API."
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
critical priorityThe flaw is in CISA KEV with known ransomware use, has an EPSS score above 0.99, and public exploit code exists, making active exploitation highly likely.
What it is
CVE-2017-0199 is a remote code execution flaw in Microsoft Office and WordPad that is triggered when a user opens a specially crafted document. The record does not specify the exact underlying coding error, and NVD classifies the weakness as insufficient information. It matters because the flaw is in widely deployed Office and Windows components and has been exploited in real attacks.
Impact
An attacker can execute arbitrary code in the context of the user who opens the document, giving full control over confidentiality, integrity and availability on that host. Because the flaw is in Office and WordPad, the attacker gains the privileges of the logged-on user rather than requiring a separate elevation step.
Attack surface
The attack is reached locally through a crafted document opened by the victim, so user interaction is required and no authentication is needed. The CVSS vector AV:L/UI:R reflects that the malicious file must be delivered to and opened on the target system.
Exploitation
Exploitation is confirmed: the CVE is in CISA's Known Exploited Vulnerabilities catalog with a known ransomware campaign use flag, and multiple references are tagged as Exploit. EPSS is 0.99933 (99.97th percentile), indicating very high predicted exploitation activity.
What to do
- Apply the Microsoft security update referenced in the vendor advisory for all affected Office, WordPad and Windows versions.
- Disable or restrict the handling of RTF and embedded OLE objects in Office where business needs allow.
- Block or quarantine untrusted Office documents at email and web gateways, and strip active content from inbound files.
- Enforce least privilege so users do not operate with administrative rights, limiting the impact of code execution.
- Use Microsoft Office Protected View and Attack Surface Reduction rules to prevent Office applications from launching child processes.
Detection
- Monitor for Office or WordPad processes spawning unexpected child processes such as cmd.exe, powershell.exe, wscript.exe or mshta.exe.
- Alert on outbound network connections or file downloads initiated by Office or WordPad processes.
- Search email and file shares for RTF and Office documents containing embedded OLE objects or remote template references.
- Review endpoint telemetry for known exploit artifacts associated with CVE-2017-0199, such as HTA handler abuse.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2017-0199 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Microsoft Office and WordPad Remote Code Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2017-0199 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-0199), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.