← Vulnerability feed

Vulnerability record · CVE-2017-11882 · published 15 November 2017

CVE-2017-11882: Microsoft Office memory corruption allows arbitrary code execution

Microsoft · Office

Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1 and 2016 fail to properly handle objects in memory, a buffer overflow (CWE-119) that lets an attacker execute arbitrary code in the context of the current user. The flaw is remotely reachable through a crafted document and has been widely exploited, including in ransomware campaigns, making it a high-value target for phishing-based intrusion.

7.8 CVSS 3.1 High CISA KEV since 3 Nov 2021 Known ransomware use EPSS 100% · top 0.1% CWE-119 · Memory buffer overflow
7.8CVSS 3.1 base score, v2 9.3
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
29References, 20 tagged exploit
17 Jun 2026Last modified by NVD

Description

Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Microsoft Office 2016 allow an attacker to run arbitrary code in the context of the current user by failing to properly handle objects in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11884.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityIt is in CISA KEV with known ransomware use, has near-certain EPSS probability and public exploit code, and grants code execution from a document open.

What it is

Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1 and 2016 fail to properly handle objects in memory, a buffer overflow (CWE-119) that lets an attacker execute arbitrary code in the context of the current user. The flaw is remotely reachable through a crafted document and has been widely exploited, including in ransomware campaigns, making it a high-value target for phishing-based intrusion.

Impact

An attacker who gets a victim to open a malicious Office file gains code execution with the victim's privileges, enabling malware installation, credential theft and lateral movement. Because the code runs as the current user, impact depends on that user's rights but can include full control of the host.

Attack surface

Reached by delivering a crafted Office document that the user must open; the CVSS vector is local with user interaction required (AV:L/AC:L/PR:N/UI:R), so no authentication is needed but a victim must be induced to open the file.

Exploitation

Listed in CISA KEV since 2021-11-03 with known ransomware campaign use, and EPSS 30-day probability is 0.99945 (99.97th percentile); multiple public exploit references and a Metasploit module exist.

What to do

  • Apply the Microsoft security update for CVE-2017-11882 on all affected Office versions (2007 SP3, 2010 SP2, 2013 SP1, 2016) as the first action.
  • Where patching is delayed, apply the vendor workaround of disabling the Equation Editor (EQNEDT32.EXE) or use third-party micropatching such as 0patch.
  • Block or strip risky Office file types at email and web gateways, and enforce Mark-of-the-Web/Protected View so documents open in a restricted mode.
  • Remove or restrict legacy Office versions that are no longer supported and cannot be patched.
  • Run users with least privilege to limit the impact of code execution in the user context.

Detection

  • Monitor for EQNEDT32.EXE spawning child processes such as cmd.exe, powershell.exe or mshta.exe, which is abnormal for the Equation Editor.
  • Alert on Office applications (WINWORD.EXE) creating executable files or launching script interpreters from temp or user-writable directories.
  • Hunt for known exploit document indicators and Equation Editor object abuse in email attachments and file shares.
  • Review endpoint telemetry for process chains where an Office document open is immediately followed by outbound network connections or credential access.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2017-11882 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Microsoft Office Memory Corruption Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://reversingminds-blog.logdown.com/posts/3907313-fileless-attack-in-word-without-macros-cve-2017-11882 ExploitThird Party Advisory
http://www.securityfocus.com/bid/101757 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1039783 Third Party AdvisoryVDB Entry
https://0patch.blogspot.com/2017/11/did-microsoft-just-manually-patch-their.html ExploitThird Party Advisory
https://0patch.blogspot.com/2017/11/official-patch-for-cve-2017-11882-meets.html ExploitPatchThird Party Advisory
https://github.com/0x09AL/CVE-2017-11882-metasploit ExploitThird Party Advisory
https://github.com/embedi/CVE-2017-11882 ExploitThird Party Advisory
https://github.com/rxwx/CVE-2017-11882 ExploitThird Party Advisory
https://github.com/unamer/CVE-2017-11882 ExploitThird Party Advisory
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11882 PatchVendor Advisory
https://researchcenter.paloaltonetworks.com/2017/12/unit42-analysis-of-cve-2017-11882-exploit-in-the-wild/ ExploitThird Party Advisory
https://web.archive.org/web/20181104111128/https://embedi.com/blog/skeleton-closet-ms-office-vulnerability-you-didnt-kno ExploitMitigationThird Party Advisory
https://www.exploit-db.com/exploits/43163/ ExploitThird Party AdvisoryVDB Entry
https://www.kb.cert.org/vuls/id/421280 Third Party AdvisoryUS Government Resource
http://reversingminds-blog.logdown.com/posts/3907313-fileless-attack-in-word-without-macros-cve-2017-11882 ExploitThird Party Advisory
http://www.securityfocus.com/bid/101757 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1039783 Third Party AdvisoryVDB Entry
https://0patch.blogspot.com/2017/11/did-microsoft-just-manually-patch-their.html ExploitThird Party Advisory
https://0patch.blogspot.com/2017/11/official-patch-for-cve-2017-11882-meets.html ExploitPatchThird Party Advisory
https://github.com/0x09AL/CVE-2017-11882-metasploit ExploitThird Party Advisory
https://github.com/embedi/CVE-2017-11882 ExploitThird Party Advisory
https://github.com/rxwx/CVE-2017-11882 ExploitThird Party Advisory
https://github.com/unamer/CVE-2017-11882 ExploitThird Party Advisory
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11882 PatchVendor Advisory
https://researchcenter.paloaltonetworks.com/2017/12/unit42-analysis-of-cve-2017-11882-exploit-in-the-wild/ ExploitThird Party Advisory
https://web.archive.org/web/20181104111128/https://embedi.com/blog/skeleton-closet-ms-office-vulnerability-you-didnt-kno ExploitMitigationThird Party Advisory
https://www.exploit-db.com/exploits/43163/ ExploitThird Party AdvisoryVDB Entry
https://www.kb.cert.org/vuls/id/421280 Third Party AdvisoryUS Government Resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-11882 US Government Resource

Track CVE-2017-11882 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-23397Microsoft Outlook improper input validation privilege escalationCVE-2023-23397 is a critical elevation of privilege flaw in Microsoft Outlook caused by improper input validation and an authentication bypass by cap…KEVEPSS 97%analysed8.8CVE-2023-35311Microsoft Outlook security feature bypass via TOCTOU race conditionCVE-2023-35311 is a security feature bypass in Microsoft Outlook caused by a time-of-check time-of-use (TOCTOU) race condition (CWE-367). It affects …KEVEPSS 16%analysed8.8CVE-2019-1297Microsoft Excel memory handling flaw allows remote code executionCVE-2019-1297 is a remote code execution vulnerability in Microsoft Excel caused by improper handling of objects in memory. An attacker who convinces…KEVEPSS 22%analysed8.8CVE-2019-0541Microsoft MSHTML engine input validation flaw allows remote code executionThe MSHTML engine in Microsoft Office, Internet Explorer and related viewers fails to properly validate input, allowing remote code execution. Becaus…KEVEPSS 53%analysed8.8CVE-2018-0798Microsoft Office Equation Editor memory corruption RCEEquation Editor in Microsoft Office 2007 through 2016 mishandles objects in memory, producing an out-of-bounds write (CWE-787) that can be turned int…KEVEPSS 95%analysed8.8CVE-2015-2424Microsoft Office memory corruption via crafted documentCVE-2015-2424 is an out-of-bounds write (CWE-787) in Microsoft PowerPoint and Word that is triggered when a crafted Office document is opened. A remo…KEVEPSS 40%analysed8.8CVE-2015-1770Microsoft Office uninitialized memory use allows remote code executionMicrosoft Office 2013 SP1 and 2013 RT SP1 mishandle uninitialized memory when parsing a crafted Office document, which can lead to arbitrary code exe…KEVEPSS 35%analysed8.8CVE-2012-1856Microsoft Office MSCOMCTL.OCX TabStrip ActiveX Control Remote Code ExecutionThe TabStrip ActiveX control in MSCOMCTL.OCX fails to properly handle system state, allowing a crafted document or web page to corrupt memory and exe…KEVEPSS 72%analysed

Source: NIST National Vulnerability Database (record CVE-2017-11882), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.