LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2017-11882: Microsoft Office Memory Corruption Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2017-11882 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Microsoft Office contains a memory corruption vulnerability that allows remote code execution in the context of the current user.

CVE-2017-11882 is a memory corruption vulnerability in Microsoft Office that can allow an attacker to run code in the context of the signed-in user. Because Office is widely deployed on endpoints that handle documents from email and shared drives, successful abuse can lead to full user-level compromise and has been associated with ransomware activity. Defenders should treat it as a high-priority patching and detection item and confirm all version and configuration details against the vendor advisory.

How it works

The weakness is classified as CWE-119 (improper restriction of operations within the bounds of a memory buffer). In products of this class, malformed input can corrupt memory structures the application uses while parsing or rendering content. An attacker who can deliver a crafted Office file—commonly via email attachment, download, or shared link—may trigger the corruption when the file is opened or previewed. If exploitation succeeds, the attacker’s code runs with the privileges of the current user, which is often enough to establish persistence, steal credentials, move laterally, or deploy follow-on payloads such as ransomware. Exact trigger conditions and exploit mechanics vary; treat public proof-of-concept claims cautiously and validate behavior only in controlled labs against the vendor’s description.

Am I affected? How to find it in your systems

Microsoft Office is typically installed on Windows workstations, laptops, and some terminal or VDI environments used by knowledge workers. Inventory every endpoint and image that includes Word, Excel, PowerPoint, or related Office components. Use your software asset management, SCCM/Intune, or endpoint management console to list installed Office editions and build numbers, then compare them to the fixed versions listed in the Microsoft security update guide for CVE-2017-11882. Also check systems that open Office documents automatically (mail gateways with preview, file servers with indexing, or collaboration platforms).

For signs of exploitation, review endpoint detection and response (EDR) telemetry for unusual child processes spawned by Office applications (winword.exe, excel.exe, powerpnt.exe), unexpected network connections originating from those processes, or crashes and faulting modules consistent with memory corruption. Email gateway and proxy logs may show delivery of suspicious Office attachments shortly before alerts. Correlate any such activity with the presence of unpatched Office builds. Confirm exact indicators and fixed builds against the vendor advisory; do not rely solely on generic signatures.

How to remediate

Patch first. Apply the Microsoft security updates that address CVE-2017-11882 exactly as directed in the vendor advisory and CISA’s required action: “Apply updates per vendor instructions.” Deploy through your normal test-and-rollout process, prioritizing internet-facing and high-risk user populations. After patching, verify the update is present via inventory or compliance reports.

Beyond the patch, harden the Office attack surface for this class of flaw: enforce Protected View for files from the internet and email, disable unnecessary legacy format support or ActiveX where business-feasible, run Office with least privilege (standard user accounts), and enable attack-surface reduction rules that block Office from creating child processes or injecting into other processes. Keep endpoint protection and EDR signatures current so post-exploitation behavior is more likely to be caught.

If you can't patch immediately

If immediate patching is blocked by change windows or compatibility testing, reduce exposure with compensating controls. Segment user workstations from critical servers and limit outbound traffic from Office processes to only required destinations. Where available, use virtual patching or email/web gateway rules that quarantine or sandbox Office documents matching known malicious patterns for this vulnerability class. Disable automatic preview panes and restrict opening of documents from untrusted zones. Increase monitoring: alert on Office spawning cmd.exe, powershell.exe, or unusual binaries, and on rapid successive crashes of Office applications. These measures lower risk but do not replace the vendor update; schedule the patch as soon as practicable.

If your data may have been exposed

Actively exploited vulnerabilities, including those known to be used with ransomware, frequently lead to credential theft, data staging, and extortion. If you have evidence of exploitation or unpatched systems that handled sensitive files, follow your incident-response plan: isolate affected hosts, preserve forensic images, reset credentials for the impacted user context, and hunt for persistence and lateral movement. As a further check on whether associated identities appear in known breach datasets, you can run a free exposure scan of your email addresses.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Office
WeaknessCWE-119
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities