← Vulnerability feed

Vulnerability record · CVE-2017-0199 · published 12 April 2017

CVE-2017-0199: Microsoft Office and WordPad remote code execution via crafted document

Microsoft · Office

CVE-2017-0199 is a remote code execution flaw in Microsoft Office and WordPad that is triggered when a user opens a specially crafted document. The record does not specify the exact underlying coding error, and NVD classifies the weakness as insufficient information. It matters because the flaw is in widely deployed Office and Windows components and has been exploited in real attacks.

7.8 CVSS 3.1 High CISA KEV since 3 Nov 2021 Known ransomware use EPSS 99% · top 0.1%
7.8CVSS 3.1 base score, v2 9.3
99%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
6Affected product versions listed by NVD
23References, 12 tagged exploit
17 Jun 2026Last modified by NVD

Description

Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, Windows 8.1 allow remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office/WordPad Remote Code Execution Vulnerability w/Windows API."

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityThe flaw is in CISA KEV with known ransomware use, has an EPSS score above 0.99, and public exploit code exists, making active exploitation highly likely.

What it is

CVE-2017-0199 is a remote code execution flaw in Microsoft Office and WordPad that is triggered when a user opens a specially crafted document. The record does not specify the exact underlying coding error, and NVD classifies the weakness as insufficient information. It matters because the flaw is in widely deployed Office and Windows components and has been exploited in real attacks.

Impact

An attacker can execute arbitrary code in the context of the user who opens the document, giving full control over confidentiality, integrity and availability on that host. Because the flaw is in Office and WordPad, the attacker gains the privileges of the logged-on user rather than requiring a separate elevation step.

Attack surface

The attack is reached locally through a crafted document opened by the victim, so user interaction is required and no authentication is needed. The CVSS vector AV:L/UI:R reflects that the malicious file must be delivered to and opened on the target system.

Exploitation

Exploitation is confirmed: the CVE is in CISA's Known Exploited Vulnerabilities catalog with a known ransomware campaign use flag, and multiple references are tagged as Exploit. EPSS is 0.99933 (99.97th percentile), indicating very high predicted exploitation activity.

What to do

  • Apply the Microsoft security update referenced in the vendor advisory for all affected Office, WordPad and Windows versions.
  • Disable or restrict the handling of RTF and embedded OLE objects in Office where business needs allow.
  • Block or quarantine untrusted Office documents at email and web gateways, and strip active content from inbound files.
  • Enforce least privilege so users do not operate with administrative rights, limiting the impact of code execution.
  • Use Microsoft Office Protected View and Attack Surface Reduction rules to prevent Office applications from launching child processes.

Detection

  • Monitor for Office or WordPad processes spawning unexpected child processes such as cmd.exe, powershell.exe, wscript.exe or mshta.exe.
  • Alert on outbound network connections or file downloads initiated by Office or WordPad processes.
  • Search email and file shares for RTF and Office documents containing embedded OLE objects or remote template references.
  • Review endpoint telemetry for known exploit artifacts associated with CVE-2017-0199, such as HTA handler abuse.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2017-0199 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Microsoft Office and WordPad Remote Code Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Affected products

6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://rewtin.blogspot.nl/2017/04/cve-2017-0199-practical-exploitation-poc.html ExploitThird Party Advisory
http://www.securityfocus.com/bid/97498 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1038224 Broken LinkThird Party AdvisoryVDB Entry
https://blog.nviso.be/2017/04/12/analysis-of-a-cve-2017-0199-malicious-rtf-document/ ExploitThird Party Advisory
https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02 Third Party AdvisoryUS Government Resource
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0199 PatchVendor Advisory
https://www.exploit-db.com/exploits/41894/ ExploitThird Party AdvisoryVDB Entry
https://www.exploit-db.com/exploits/41934/ ExploitThird Party AdvisoryVDB Entry
https://www.exploit-db.com/exploits/42995/ Third Party AdvisoryVDB Entry
https://www.fireeye.com/blog/threat-research/2017/04/cve-2017-0199_useda.html Broken LinkExploitThird Party Advisory
https://www.mdsec.co.uk/2017/04/exploiting-cve-2017-0199-hta-handler-vulnerability/ ExploitThird Party Advisory
http://rewtin.blogspot.nl/2017/04/cve-2017-0199-practical-exploitation-poc.html ExploitThird Party Advisory
http://www.securityfocus.com/bid/97498 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1038224 Broken LinkThird Party AdvisoryVDB Entry
https://blog.nviso.be/2017/04/12/analysis-of-a-cve-2017-0199-malicious-rtf-document/ ExploitThird Party Advisory
https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02 Third Party AdvisoryUS Government Resource
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0199 PatchVendor Advisory
https://www.exploit-db.com/exploits/41894/ ExploitThird Party AdvisoryVDB Entry
https://www.exploit-db.com/exploits/41934/ ExploitThird Party AdvisoryVDB Entry
https://www.exploit-db.com/exploits/42995/ Third Party AdvisoryVDB Entry
https://www.fireeye.com/blog/threat-research/2017/04/cve-2017-0199_useda.html Broken LinkExploitThird Party Advisory
https://www.mdsec.co.uk/2017/04/exploiting-cve-2017-0199-hta-handler-vulnerability/ ExploitThird Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-0199 US Government Resource

Track CVE-2017-0199 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2020-1350Windows DNS Server improper input validation remote code executionWindows DNS servers fail to properly handle certain requests, allowing remote code execution. The flaw is network-reachable, needs no authentication …KEVEPSS 97%analysed9.8CVE-2025-59287Microsoft WSUS deserialization flaw allows unauthenticated remote code executionWindows Server Update Service (WSUS) deserializes untrusted data, letting an unauthenticated network attacker run code on the server. The flaw is rat…KEVEPSS 100%analysed9.8CVE-2023-23397Microsoft Outlook improper input validation privilege escalationCVE-2023-23397 is a critical elevation of privilege flaw in Microsoft Outlook caused by improper input validation and an authentication bypass by cap…KEVEPSS 97%analysed9.8CVE-2019-0708Microsoft Remote Desktop Services use-after-free remote code executionRemote Desktop Services (formerly Terminal Services) contains a use-after-free flaw that lets an unauthenticated attacker execute code by sending spe…KEVEPSS 100%analysed9.8CVE-2017-8543Windows Search memory handling flaw allows remote code executionWindows Search fails to properly handle objects in memory, allowing an unauthenticated remote attacker to execute code on affected Windows systems. T…KEVEPSS 74%analysed9.8CVE-2015-1635Microsoft HTTP.sys remote code execution via crafted HTTP requestsHTTP.sys in multiple Windows versions fails to properly handle crafted HTTP requests, allowing remote code execution. The flaw is reachable over the …KEVEPSS 100%analysed9.8CVE-2008-4250Microsoft Windows Server service RPC path canonicalization buffer overflowThe Server service in multiple Windows versions fails to properly handle path canonicalization, allowing a crafted RPC request to overflow a buffer a…KEVEPSS 99%analysed9.0CVE-2020-1040Microsoft Hyper-V RemoteFX vGPU input validation remote code executionHyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user on a guest operating system, allowing remote code …KEVEPSS 7.4%analysed

Source: NIST National Vulnerability Database (record CVE-2017-0199), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.