Junglewise Threat Intelligence

CVE-2017-0261: Microsoft Office Use-After-Free Vulnerability

CVE-2017-0261 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-03-03

Technologies: Microsoft Office, Microsoft Office 2016. Vendors: Microsoft.

Executive brief

Microsoft Office contains a use-after-free vulnerability (CWE-416) when handling objects in memory. This flaw allows a remote attacker to execute arbitrary code on a target system if a user opens a specially crafted file.

Affected products

  • Microsoft Office 2010 SP2
  • Microsoft Office 2013 SP1
  • Microsoft Office 2016

Timeline

  • 2017-05-12: disclosed: NVD Published Date
  • 2017-05-12: advisory: MSRC advisory published
  • 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats