Junglewise Threat Intelligence

CVE-2017-0262: Microsoft Office Remote Code Execution Vulnerability

CVE-2017-0262 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-02-10

Technologies: Microsoft Office 2016, Microsoft Office. Vendors: Microsoft.

Executive brief

A remote code execution vulnerability exists in Microsoft Office 2010, 2013, and 2016 when the software fails to properly handle objects in memory. An attacker could exploit this by convincing a user to open a specially crafted file, leading to full system compromise.

Affected products

  • Microsoft Office 2010 SP2
  • Microsoft Office 2013 SP1
  • Microsoft Office 2016 -

Timeline

  • 2017-05-12: disclosed: NVD Published Date
  • 2022-02-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats