Junglewise Threat Intelligence

CVE-2017-11882: Microsoft Office Memory Corruption Vulnerability

CVE-2017-11882 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2021-11-03

Technologies: Microsoft Office, Microsoft Office 2016. Vendors: Microsoft.

Executive brief

Microsoft Office contains a memory corruption vulnerability (CWE-119) due to improper handling of objects in memory. An attacker can exploit this to execute arbitrary code in the context of the current user, typically requiring a user to open a specially crafted file.

Affected products

  • Microsoft Office 2007 Service Pack 3
  • Microsoft Office 2010 Service Pack 2
  • Microsoft Office 2013 Service Pack 1
  • Microsoft Office 2016

Timeline

  • 2017-11-14: patched: Microsoft released security guidance and patches.
  • 2017-11-14: disclosed: Initial public disclosure and advisory publication.
  • 2021-11-03: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog.

Related threats