Executive brief
Equation Editor in Microsoft Office contains a memory corruption vulnerability due to improper object handling in memory. A remote attacker can exploit this to execute arbitrary code in the context of the current user, often by chaining it with other vulnerabilities like CVE-2018-0802.
Affected products
- Microsoft Office 2007 Service Pack 3
- Microsoft Office 2010 Service Pack 2
- Microsoft Office 2013 Service Pack 1
- Microsoft Office 2016
- Microsoft Word 2007 Service Pack 3
- Microsoft Word 2010 Service Pack 2
- Microsoft Word 2013 Service Pack 1
- Microsoft Word 2016
Timeline
- 2018-01-09: disclosed: Initial advisory and third-party analysis published.
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
- 2021-11-03: exploited: Confirmed as exploited in the wild.