Junglewise Threat Intelligence

CVE-2017-0199: Microsoft Office and WordPad Remote Code Execution Vulnerability

CVE-2017-0199 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2021-11-03

Technologies: Microsoft Windows Vista, Microsoft Office 2016, Microsoft Windows 8.1, Microsoft Office, Microsoft Windows Server 2008, Microsoft Windows Server 2012, Microsoft Windows 7. Vendors: Microsoft.

Executive brief

Microsoft Office and WordPad contain a remote code execution vulnerability due to the way the applications parse specially crafted documents. Attackers can execute arbitrary code via a malicious file, leveraging the Windows API.

Affected products

  • Microsoft Office 2007 SP3
  • Microsoft Office 2010 SP2
  • Microsoft Office 2013 SP1
  • Microsoft Office 2016 -
  • Microsoft Windows Vista SP2
  • Microsoft Windows Server 2008 SP2
  • Microsoft Windows 7 SP1
  • Microsoft Windows 8.1 -
  • Microsoft Windows Server 2012 -

Timeline

  • 2017-04-11: advisory: MSRC advisory published
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats