LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2017-0261: Microsoft Office Use-After-Free Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 3, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 24, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2017-0261 to its Known Exploited Vulnerabilities catalog on Mar 3, 2022, with a federal patch deadline of Mar 24, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft Office contains a use-after-free vulnerability which can allow for remote code execution.

CVE-2017-0261 is a use-after-free vulnerability in Microsoft Office that can allow remote code execution. An attacker who successfully exploits it may run code in the context of the user opening a crafted Office file or document. For IT and security teams, this matters because Office is widely deployed on endpoints and often processes untrusted content from email or shared drives, creating a practical path to initial access if systems remain unpatched.

Public detail is limited to the CISA summary and the stated weakness class. Confirm exact affected products, builds, and attack vectors against the vendor advisory before prioritizing response.

How it works

This issue is classified as CWE-416 (use-after-free). In this class of flaw, memory that has already been freed is referenced again. If an attacker can control the data that occupies that memory region after it is freed, they may corrupt program state or redirect execution.

In the context of Microsoft Office, the CISA summary states the vulnerability can allow remote code execution. Typical abuse for this product class involves a malicious document or related Office content that triggers the flawed code path when opened or previewed. Specifics of the free and reuse sequence, required user interaction, or exact trigger conditions are not provided in the given facts and must be confirmed against the vendor advisory. Do not assume particular exploit mechanics beyond the stated use-after-free leading to possible code execution.

Am I affected? How to find it in your systems

Microsoft Office is commonly installed on Windows workstations, laptops, and some servers used for document processing or automation. Inventory every host that has Office components, including full suites, standalone applications, and any viewer or compatibility packs that may share the vulnerable code.

How to remediate

Patch first. CISA required action is to apply updates per vendor instructions. Obtain and deploy the security updates Microsoft released for this CVE through your normal patching channel (WSUS, Microsoft Update, ConfigMgr, Intune, or equivalent). Verify installation by confirming the post-patch build numbers match the advisory.

After patching, apply hardening appropriate to the Office attack surface:

If you can't patch immediately

Reduce exposure until the vendor update can be applied:

If your data may have been exposed

Actively exploited vulnerabilities can lead to endpoint compromise and subsequent data theft or ransomware, although known ransomware use is not documented for this CVE in the provided facts. If you have indicators of successful exploitation, follow your incident-response process: isolate hosts, preserve evidence, reset credentials, and assess lateral movement. As a routine check, users and administrators can run a free exposure scan of their email addresses against known breach data sets to see whether associated accounts appear in prior incidents and then enforce password changes and multifactor authentication where needed.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Office
WeaknessCWE-416
Added to CISA KEVMar 3, 2022
Federal patch deadlineMar 24, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities