LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2018-0802: Microsoft Office Memory Corruption Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2018-0802 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Microsoft Office contains a memory corruption vulnerability due to the way objects are handled in memory. Successful exploitation allows for remote code execution in the context of the current user…

CVE-2018-0802 is a memory corruption vulnerability in Microsoft Office that arises from the way the software handles objects in memory. Successful exploitation can allow an attacker to execute code remotely in the context of the current user. It is known to be chained with CVE-2018-0798, which increases the practical risk for environments that still run unpatched Office installations. Defenders should treat it as a high-priority remote code execution issue in a widely deployed desktop productivity suite and confirm all version and patch details against the vendor advisory.

How it works

The underlying weakness is classified as CWE-787, an out-of-bounds write that corrupts memory. In Microsoft Office, improper handling of objects in memory can let crafted input overwrite memory outside the intended bounds. An attacker who can deliver a malicious Office document or related content may trigger this corruption to achieve remote code execution under the privileges of the logged-on user. Public detail on exact trigger conditions is limited; the CISA summary notes that the flaw stems from how objects are handled in memory and that the vulnerability has been observed chained with CVE-2018-0798. No further exploit mechanics should be assumed without reference to the vendor advisory.

Am I affected? How to find it in your systems

Microsoft Office is typically installed on Windows endpoints used by knowledge workers, including desktops, laptops, and virtual desktop infrastructure. Inventory every system that has Office components installed—word processors, spreadsheet applications, and related viewers or converters. Because exact affected builds are not listed in the provided facts, compare installed Office versions and update levels directly against the Microsoft advisory for CVE-2018-0802.

Confirm all version ranges and detection signatures against the official vendor advisory before declaring systems clean or affected.

How to remediate

The primary remediation is to apply the updates Microsoft released for this vulnerability, following the vendor instructions referenced by CISA. Deploy the security update through your normal patch management channel as soon as testing confirms compatibility.

If you can't patch immediately

When immediate patching is not feasible, apply compensating controls that limit delivery and execution of malicious Office content.

These measures reduce risk but do not replace the vendor update; schedule patching as soon as operationally possible.

If your data may have been exposed

Actively exploited memory-corruption vulnerabilities in Office can lead to endpoint compromise and subsequent data theft or lateral movement. Ransomware use specifically tied to CVE-2018-0802 is not documented in the provided facts. If you suspect exploitation, isolate affected hosts, preserve forensic evidence, and follow your incident-response process. As a quick additional check, you can run a free exposure scan of your email addresses against known breach data sets to see whether credentials or personal information have already appeared in public breach corpora.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Office
WeaknessCWE-787
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities