Vulnerability record · CVE-2017-0262 · published 12 May 2017
CVE-2017-0262: Microsoft Office memory handling flaw enables remote code execution
Microsoft · Office
Microsoft Office 2010 SP2, 2013 SP1 and 2016 fail to properly handle objects in memory, producing a remote code execution vulnerability. Because the flaw is memory-corruption related and reachable through Office document processing, it matters for any environment still running these Office versions.
Description
Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0261 and CVE-2017-0281.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw is in CISA's KEV catalog with a very high EPSS score, but exploitation requires local access and user interaction, and the affected Office versions are legacy.
What it is
Microsoft Office 2010 SP2, 2013 SP1 and 2016 fail to properly handle objects in memory, producing a remote code execution vulnerability. Because the flaw is memory-corruption related and reachable through Office document processing, it matters for any environment still running these Office versions.
Impact
An attacker who gets code to run gains execution in the context of the current user, which can lead to full compromise of that user's data and, depending on privileges, the host.
Attack surface
The CVSS vector is local with user interaction required (AV:L/UI:R), so the victim must open or interact with a crafted file; no authentication is needed (PR:N). The description does not specify the exact file format or component involved.
Exploitation
CVE-2017-0262 is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-02-10), indicating exploitation in the wild, and EPSS gives a 30-day probability of 0.81005 (99.61st percentile). No ransomware campaign use is recorded.
What to do
- Apply the Microsoft security update referenced in the MSRC advisory for CVE-2017-0262 on all affected Office 2010 SP2, 2013 SP1 and 2016 installations.
- Prioritize patching per the CISA KEV due date of 2022-08-10 if any affected systems remain unpatched.
- Block or restrict opening of untrusted Office documents from email and web sources until patching is complete.
- Enable Office Protected View and disable macros for documents from external sources to reduce the chance of successful exploitation.
- Retire or isolate end-of-support Office versions that cannot receive current security fixes.
Detection
- Monitor for Office application processes (WINWORD.EXE, EXCEL.EXE, POWERPNT.EXE) spawning child processes such as cmd.exe, powershell.exe or wscript.exe.
- Alert on Office processes making unusual network connections or writing executables to user-writable directories.
- Hunt for documents exploiting memory corruption patterns, such as malformed embedded objects, opened from email attachments or downloads.
- Correlate endpoint telemetry for crashes in Office processes followed by suspicious child process creation.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2017-0262 to the Known Exploited Vulnerabilities catalog on 10 February 2022 as "Microsoft Office Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 10 August 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/98279 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0262 | PatchVendor Advisory |
| http://www.securityfocus.com/bid/98279 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0262 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-0262 | US Government Resource |
Track CVE-2017-0262 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-0262), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.