LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2017-8570: Microsoft Office Remote Code Execution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Feb 25, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Aug 25, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2017-8570 to its Known Exploited Vulnerabilities catalog on Feb 25, 2022, with a federal patch deadline of Aug 25, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

A remote code execution vulnerability exists in Microsoft Office software when it fails to properly handle objects in memory.

CVE-2017-8570 is a remote code execution vulnerability in Microsoft Office that arises when the software fails to properly handle objects in memory. If an attacker can get a user to open a specially crafted Office file, the flaw can allow code to run in the context of that user. For IT and security teams this matters because Office is widely deployed on endpoints and is a common delivery path for initial access; successful exploitation can lead to further compromise of the workstation and the broader environment.

Public detail on exact mechanics and affected builds is limited to the vendor and CISA descriptions. Confirm all version, configuration, and patch specifics directly against the Microsoft advisory for this CVE before acting.

How it works

The vulnerability belongs to the class of memory-handling flaws in document-parsing applications. Microsoft Office processes complex file formats that contain many object types; when those objects are not validated or cleaned up correctly, an attacker-controlled file can corrupt memory in a way that redirects execution.

In practice an attacker crafts a malicious Office document and delivers it through email, a file share, a download link, or another channel that reaches the user. When the document is opened in a vulnerable Office installation, the flawed object handling can allow the attacker’s code to run with the privileges of the logged-on user. No further CWE classification or exploit-step detail is provided in the source material, so defenders should treat this as a classic Office RCE via malicious file and rely on the vendor advisory for any deeper technical notes.

Am I affected? How to find it in your systems

Microsoft Office is typically installed on Windows workstations, laptops, and some terminal servers or VDI images used by knowledge workers. Inventory every endpoint and image that has any Office application (Word, Excel, PowerPoint, Outlook, etc.) present.

If your inventory tooling cannot reliably report Office build numbers, treat those systems as potentially affected until verified.

How to remediate

The primary remediation is to apply the security updates Microsoft released for this vulnerability. Follow the vendor instructions exactly: identify the correct update package for each Office edition and channel in use, deploy it through your normal patch-management process, and verify installation success.

If you can't patch immediately

When immediate patching is not possible, apply compensating controls that reduce the likelihood of a malicious document reaching a vulnerable parser or limit the impact of successful exploitation.

These measures do not eliminate the vulnerability; they only buy time. Schedule the official update as soon as operationally feasible.

If your data may have been exposed

Actively exploited remote-code-execution vulnerabilities in desktop productivity software frequently serve as the entry point for broader incidents, including data theft. If you have evidence that a malicious Office document was opened on an unpatched system, follow your incident-response process: isolate the host, collect volatile evidence, and hunt for lateral movement or exfiltration. As a simple additional check, users can run a free exposure scan of their work email addresses against known breach data sets to see whether credentials or personal information have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Office
Added to CISA KEVFeb 25, 2022
Federal patch deadlineAug 25, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities