← Vulnerability feed

Vulnerability record · CVE-2017-0262 · published 12 May 2017

CVE-2017-0262: Microsoft Office memory handling flaw enables remote code execution

Microsoft · Office

Microsoft Office 2010 SP2, 2013 SP1 and 2016 fail to properly handle objects in memory, producing a remote code execution vulnerability. Because the flaw is memory-corruption related and reachable through Office document processing, it matters for any environment still running these Office versions.

7.8 CVSS 3.1 High CISA KEV since 10 Feb 2022 EPSS 81% · top 0.4%
7.8CVSS 3.1 base score, v2 9.3
81%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References
17 Jun 2026Last modified by NVD

Description

Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0261 and CVE-2017-0281.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

high priorityThe flaw is in CISA's KEV catalog with a very high EPSS score, but exploitation requires local access and user interaction, and the affected Office versions are legacy.

What it is

Microsoft Office 2010 SP2, 2013 SP1 and 2016 fail to properly handle objects in memory, producing a remote code execution vulnerability. Because the flaw is memory-corruption related and reachable through Office document processing, it matters for any environment still running these Office versions.

Impact

An attacker who gets code to run gains execution in the context of the current user, which can lead to full compromise of that user's data and, depending on privileges, the host.

Attack surface

The CVSS vector is local with user interaction required (AV:L/UI:R), so the victim must open or interact with a crafted file; no authentication is needed (PR:N). The description does not specify the exact file format or component involved.

Exploitation

CVE-2017-0262 is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-02-10), indicating exploitation in the wild, and EPSS gives a 30-day probability of 0.81005 (99.61st percentile). No ransomware campaign use is recorded.

What to do

  • Apply the Microsoft security update referenced in the MSRC advisory for CVE-2017-0262 on all affected Office 2010 SP2, 2013 SP1 and 2016 installations.
  • Prioritize patching per the CISA KEV due date of 2022-08-10 if any affected systems remain unpatched.
  • Block or restrict opening of untrusted Office documents from email and web sources until patching is complete.
  • Enable Office Protected View and disable macros for documents from external sources to reduce the chance of successful exploitation.
  • Retire or isolate end-of-support Office versions that cannot receive current security fixes.

Detection

  • Monitor for Office application processes (WINWORD.EXE, EXCEL.EXE, POWERPNT.EXE) spawning child processes such as cmd.exe, powershell.exe or wscript.exe.
  • Alert on Office processes making unusual network connections or writing executables to user-writable directories.
  • Hunt for documents exploiting memory corruption patterns, such as malformed embedded objects, opened from email attachments or downloads.
  • Correlate endpoint telemetry for crashes in Office processes followed by suspicious child process creation.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2017-0262 to the Known Exploited Vulnerabilities catalog on 10 February 2022 as "Microsoft Office Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 10 August 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-0262 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-23397Microsoft Outlook improper input validation privilege escalationCVE-2023-23397 is a critical elevation of privilege flaw in Microsoft Outlook caused by improper input validation and an authentication bypass by cap…KEVEPSS 97%analysed8.8CVE-2023-35311Microsoft Outlook security feature bypass via TOCTOU race conditionCVE-2023-35311 is a security feature bypass in Microsoft Outlook caused by a time-of-check time-of-use (TOCTOU) race condition (CWE-367). It affects …KEVEPSS 16%analysed8.8CVE-2019-1297Microsoft Excel memory handling flaw allows remote code executionCVE-2019-1297 is a remote code execution vulnerability in Microsoft Excel caused by improper handling of objects in memory. An attacker who convinces…KEVEPSS 22%analysed8.8CVE-2019-0541Microsoft MSHTML engine input validation flaw allows remote code executionThe MSHTML engine in Microsoft Office, Internet Explorer and related viewers fails to properly validate input, allowing remote code execution. Becaus…KEVEPSS 53%analysed8.8CVE-2018-0798Microsoft Office Equation Editor memory corruption RCEEquation Editor in Microsoft Office 2007 through 2016 mishandles objects in memory, producing an out-of-bounds write (CWE-787) that can be turned int…KEVEPSS 95%analysed8.8CVE-2015-2424Microsoft Office memory corruption via crafted documentCVE-2015-2424 is an out-of-bounds write (CWE-787) in Microsoft PowerPoint and Word that is triggered when a crafted Office document is opened. A remo…KEVEPSS 40%analysed8.8CVE-2015-1770Microsoft Office uninitialized memory use allows remote code executionMicrosoft Office 2013 SP1 and 2013 RT SP1 mishandle uninitialized memory when parsing a crafted Office document, which can lead to arbitrary code exe…KEVEPSS 35%analysed8.8CVE-2012-1856Microsoft Office MSCOMCTL.OCX TabStrip ActiveX Control Remote Code ExecutionThe TabStrip ActiveX control in MSCOMCTL.OCX fails to properly handle system state, allowing a crafted document or web page to corrupt memory and exe…KEVEPSS 72%analysed

Source: NIST National Vulnerability Database (record CVE-2017-0262), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.