Vulnerability record · CVE-2017-11882 · published 15 November 2017
CVE-2017-11882: Microsoft Office memory corruption allows arbitrary code execution
Microsoft · Office
Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1 and 2016 fail to properly handle objects in memory, a buffer overflow (CWE-119) that lets an attacker execute arbitrary code in the context of the current user. The flaw is remotely reachable through a crafted document and has been widely exploited, including in ransomware campaigns, making it a high-value target for phishing-based intrusion.
Description
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Microsoft Office 2016 allow an attacker to run arbitrary code in the context of the current user by failing to properly handle objects in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11884.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
critical priorityIt is in CISA KEV with known ransomware use, has near-certain EPSS probability and public exploit code, and grants code execution from a document open.
What it is
Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1 and 2016 fail to properly handle objects in memory, a buffer overflow (CWE-119) that lets an attacker execute arbitrary code in the context of the current user. The flaw is remotely reachable through a crafted document and has been widely exploited, including in ransomware campaigns, making it a high-value target for phishing-based intrusion.
Impact
An attacker who gets a victim to open a malicious Office file gains code execution with the victim's privileges, enabling malware installation, credential theft and lateral movement. Because the code runs as the current user, impact depends on that user's rights but can include full control of the host.
Attack surface
Reached by delivering a crafted Office document that the user must open; the CVSS vector is local with user interaction required (AV:L/AC:L/PR:N/UI:R), so no authentication is needed but a victim must be induced to open the file.
Exploitation
Listed in CISA KEV since 2021-11-03 with known ransomware campaign use, and EPSS 30-day probability is 0.99945 (99.97th percentile); multiple public exploit references and a Metasploit module exist.
What to do
- Apply the Microsoft security update for CVE-2017-11882 on all affected Office versions (2007 SP3, 2010 SP2, 2013 SP1, 2016) as the first action.
- Where patching is delayed, apply the vendor workaround of disabling the Equation Editor (EQNEDT32.EXE) or use third-party micropatching such as 0patch.
- Block or strip risky Office file types at email and web gateways, and enforce Mark-of-the-Web/Protected View so documents open in a restricted mode.
- Remove or restrict legacy Office versions that are no longer supported and cannot be patched.
- Run users with least privilege to limit the impact of code execution in the user context.
Detection
- Monitor for EQNEDT32.EXE spawning child processes such as cmd.exe, powershell.exe or mshta.exe, which is abnormal for the Equation Editor.
- Alert on Office applications (WINWORD.EXE) creating executable files or launching script interpreters from temp or user-writable directories.
- Hunt for known exploit document indicators and Equation Editor object abuse in email attachments and file shares.
- Review endpoint telemetry for process chains where an Office document open is immediately followed by outbound network connections or credential access.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2017-11882 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Microsoft Office Memory Corruption Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2017-11882 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-11882), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.