Vulnerability record · CVE-2017-11826 · published 13 October 2017
CVE-2017-11826: Microsoft Office memory corruption allows remote code execution
Microsoft · Office Compatibility Pack
Microsoft Office, Word, SharePoint, Office Web Apps and related products fail to properly handle objects in memory, a buffer overflow (CWE-119) that permits remote code execution. Because the affected software is widely deployed and the flaw was exploited as a zero-day, it remains a serious risk to unpatched endpoints and document-processing services.
Description
Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word Viewer, Word 2007, 2010, 2013 and 2016, Word Automation Services, and Office Online Server allow remote code execution when the software fails to properly handle objects in memory.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw is in CISA KEV with public exploit code and a very high EPSS score, but exploitation requires a user to open a crafted document, which limits mass exploitation.
What it is
Microsoft Office, Word, SharePoint, Office Web Apps and related products fail to properly handle objects in memory, a buffer overflow (CWE-119) that permits remote code execution. Because the affected software is widely deployed and the flaw was exploited as a zero-day, it remains a serious risk to unpatched endpoints and document-processing services.
Impact
An attacker who gets a crafted document opened can execute arbitrary code in the context of the current user, giving full control of confidentiality, integrity and availability on that host.
Attack surface
Reached locally via a malicious file or document that the victim must open (CVSS vector AV:L/UI:R, PR:N), so no authentication is required but user interaction is needed. The same memory-handling flaw affects server-side document processing components such as SharePoint and Office Online Server.
Exploitation
Listed in CISA KEV since 2022-03-03 with a required action to patch, and EPSS 30-day probability is 0.813 (99.6th percentile). Multiple references are tagged Exploit, including a 0patch write-up and a Tarlogic exploitation analysis, confirming public exploit material.
What to do
- Apply the Microsoft security update referenced in the MSRC advisory for CVE-2017-11826 to all affected Office, Word, SharePoint, Office Web Apps and Office Online Server installations.
- Where legacy products cannot be patched, remove or isolate them and use 0patch or equivalent temporary mitigations only as a stopgap.
- Block or sandbox untrusted Office documents at email and web gateways, and disable macros and ActiveX where not required.
- Run Office and document-processing services with least privilege and enable Protected View / Application Guard for files from untrusted sources.
- Retire end-of-support products such as Office 2010, Word Viewer and SharePoint 2010 that no longer receive security fixes.
Detection
- Monitor for Office or Word processes spawning unexpected child processes such as cmd.exe, powershell.exe or wscript.exe.
- Alert on document files written to temp or startup locations by Office applications, and on Office making unusual outbound network connections.
- Hunt for known exploit document indicators and memory-corruption crash patterns in Word, SharePoint or Office Online Server logs.
- Track unpatched hosts still running the affected Office, Word Viewer, SharePoint and Office Web Apps versions.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2017-11826 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Microsoft Office Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 24 March 2022.
Affected products
7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2017-11826 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-11826), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.