← Vulnerability feed

Vulnerability record · CVE-2017-11826 · published 13 October 2017

CVE-2017-11826: Microsoft Office memory corruption allows remote code execution

Microsoft · Office Compatibility Pack

Microsoft Office, Word, SharePoint, Office Web Apps and related products fail to properly handle objects in memory, a buffer overflow (CWE-119) that permits remote code execution. Because the affected software is widely deployed and the flaw was exploited as a zero-day, it remains a serious risk to unpatched endpoints and document-processing services.

7.8 CVSS 3.1 High CISA KEV since 3 Mar 2022 EPSS 81% · top 0.4% CWE-119 · Memory buffer overflow
7.8CVSS 3.1 base score, v2 9.3
81%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
7Affected product versions listed by NVD
13References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word Viewer, Word 2007, 2010, 2013 and 2016, Word Automation Services, and Office Online Server allow remote code execution when the software fails to properly handle objects in memory.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityThe flaw is in CISA KEV with public exploit code and a very high EPSS score, but exploitation requires a user to open a crafted document, which limits mass exploitation.

What it is

Microsoft Office, Word, SharePoint, Office Web Apps and related products fail to properly handle objects in memory, a buffer overflow (CWE-119) that permits remote code execution. Because the affected software is widely deployed and the flaw was exploited as a zero-day, it remains a serious risk to unpatched endpoints and document-processing services.

Impact

An attacker who gets a crafted document opened can execute arbitrary code in the context of the current user, giving full control of confidentiality, integrity and availability on that host.

Attack surface

Reached locally via a malicious file or document that the victim must open (CVSS vector AV:L/UI:R, PR:N), so no authentication is required but user interaction is needed. The same memory-handling flaw affects server-side document processing components such as SharePoint and Office Online Server.

Exploitation

Listed in CISA KEV since 2022-03-03 with a required action to patch, and EPSS 30-day probability is 0.813 (99.6th percentile). Multiple references are tagged Exploit, including a 0patch write-up and a Tarlogic exploitation analysis, confirming public exploit material.

What to do

  • Apply the Microsoft security update referenced in the MSRC advisory for CVE-2017-11826 to all affected Office, Word, SharePoint, Office Web Apps and Office Online Server installations.
  • Where legacy products cannot be patched, remove or isolate them and use 0patch or equivalent temporary mitigations only as a stopgap.
  • Block or sandbox untrusted Office documents at email and web gateways, and disable macros and ActiveX where not required.
  • Run Office and document-processing services with least privilege and enable Protected View / Application Guard for files from untrusted sources.
  • Retire end-of-support products such as Office 2010, Word Viewer and SharePoint 2010 that no longer receive security fixes.

Detection

  • Monitor for Office or Word processes spawning unexpected child processes such as cmd.exe, powershell.exe or wscript.exe.
  • Alert on document files written to temp or startup locations by Office applications, and on Office making unusual outbound network connections.
  • Hunt for known exploit document indicators and memory-corruption crash patterns in Word, SharePoint or Office Online Server logs.
  • Track unpatched hosts still running the affected Office, Word Viewer, SharePoint and Office Web Apps versions.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2017-11826 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Microsoft Office Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 24 March 2022.

Affected products

7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-11826 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-0604Microsoft SharePoint application package markup validation RCEMicrosoft SharePoint fails to validate the source markup of an application package, allowing crafted packages to execute code on the server. This is …KEVEPSS 100%analysed8.8CVE-2019-0541Microsoft MSHTML engine input validation flaw allows remote code executionThe MSHTML engine in Microsoft Office, Internet Explorer and related viewers fails to properly validate input, allowing remote code execution. Becaus…KEVEPSS 53%analysed8.8CVE-2018-0798Microsoft Office Equation Editor memory corruption RCEEquation Editor in Microsoft Office 2007 through 2016 mishandles objects in memory, producing an out-of-bounds write (CWE-787) that can be turned int…KEVEPSS 95%analysed8.8CVE-2015-2424Microsoft Office memory corruption via crafted documentCVE-2015-2424 is an out-of-bounds write (CWE-787) in Microsoft PowerPoint and Word that is triggered when a crafted Office document is opened. A remo…KEVEPSS 40%analysed8.8CVE-2009-0238Microsoft Excel invalid object access allows remote code executionMicrosoft Excel and related viewers (Excel 2000 through 2007, Excel Viewer, Office Compatibility Pack, and Office for Mac 2004/2008) fail to handle a…KEVEPSS 43%analysed7.8CVE-2020-1147Microsoft .NET Framework, SharePoint, and Visual Studio XML Deserialization RCEThe software fails to check the source markup of XML input, allowing crafted XML to trigger unsafe deserialization and remote code execution. It affe…KEVEPSS 94%analysed7.8CVE-2018-0802Microsoft Office Equation Editor Memory Corruption RCEEquation Editor in Microsoft Office 2007, 2010, 2013, and 2016 mishandles objects in memory, causing an out-of-bounds write (CWE-787) that can lead t…KEVEPSS 93%analysed7.8CVE-2016-7262Microsoft Excel security feature bypass enables command executionA crafted cell in affected Microsoft Excel and Excel Viewer versions is mishandled when a user clicks it, allowing a security feature bypass that lea…KEVEPSS 58%analysed

Source: NIST National Vulnerability Database (record CVE-2017-11826), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.