LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2017-11826: Microsoft Office Remote Code Execution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 3, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 24, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2017-11826 to its Known Exploited Vulnerabilities catalog on Mar 3, 2022, with a federal patch deadline of Mar 24, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could…

CVE-2017-11826 is a remote code execution vulnerability in Microsoft Office that arises when the software fails to properly handle objects in memory. An attacker who successfully exploits it could run arbitrary code in the context of the current user. For IT and security teams, this matters because Office is widely deployed on endpoints and often processes untrusted documents; successful abuse can lead to code execution under the logged-on user and potential follow-on activity on the host.

Public detail is limited to the vendor and CISA descriptions; confirm exact affected products, builds, and fixes against the official Microsoft advisory before acting.

How it works

The weakness is classified as CWE-119 (improper restriction of operations within the bounds of a memory buffer). In this class of flaw, software mishandles memory objects so that crafted input can corrupt memory structures. Per the CISA summary, Microsoft Office fails to properly handle objects in memory; an attacker who successfully exploits the vulnerability could run arbitrary code in the context of the current user.

In practical terms for this product class, abuse typically involves delivering a specially crafted Office file that the victim opens or previews. The malformed content triggers the memory-handling error, allowing the attacker’s code to execute with the privileges of the user who opened the document. Specifics of the trigger, object type, or exploitation path are not provided in the given facts and must be confirmed against the vendor advisory. Do not assume particular file formats or delivery methods beyond what the advisory states.

Am I affected? How to find it in your systems

Microsoft Office commonly runs on Windows workstations, laptops, and some servers or terminal services hosts used for document processing. Inventory all systems that have Office components installed, including full suites, standalone applications, and any viewer or compatibility packs that may share the vulnerable code path.

How to remediate

Patch first. Apply the updates Microsoft released for this vulnerability exactly as directed in the vendor advisory. CISA’s required action is to apply updates per vendor instructions. Prioritize systems that process documents from external or untrusted sources.

If you can't patch immediately

Reduce risk with compensating controls until the vendor update can be applied.

If your data may have been exposed

Actively exploited remote-code-execution vulnerabilities in desktop productivity software can lead to endpoint compromise and subsequent data access under the user’s context. Known ransomware use is not documented for this CVE in the provided facts. If you suspect successful exploitation, isolate affected hosts, preserve volatile evidence, credential-reset the involved accounts, and follow your incident-response process. As a further check, you can run a free exposure scan of your email addresses against known breach data to see whether credentials or personal information have appeared in prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Office
WeaknessCWE-119
Added to CISA KEVMar 3, 2022
Federal patch deadlineMar 24, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities