CVE-2017-0199General(microsoft / intellispace_portal)

MEDIUMCVSS 7.8 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for microsoft intellispace_portal systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, Windows 8.1 allow remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office/WordPad Remote Code Execution Vulnerability w/Windows API."

4.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-05-03. Apply updates per vendor instructions.

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • intellispace_portal
  • office
  • windows_7
  • windows_server_2008

Threat summary

  • Active exploitation appears in 2 classified signals
  • 8 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Technical details provided in 1 signal
  • General: 4 classified signals
  • Peaked 4d ago at 2 mentions (2026-06-30); latest day: 1
  • 8 total mentions across 7 days

Affected systems

Products
intellispace_portalofficewindows_7windows_server_2008windows_server_2012windows_vista

8 versions affected across 6 products

Deep dive

Activity timeline8 mentions / 7d
01122Mentions · 2026-03-04: 1Mentions · 2026-05-15: 1Mentions · 2026-06-30: 2Mentions · 2026-07-11: 1Mentions · 2026-08-24: 1Mentions · 2026-09-29: 1Mentions · 2026-09-30: 1Active Exploitation · 2026-07-11: 1Active Exploitation · 2026-08-24: 1Technical Details · 2026-07-11: 103-0405-1506-3007-1108-2409-2909-30
Signal classification2 categories
General
466.7%
Active Exploitation
233.3%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-03-041
General1
2026-05-151
General1
2026-06-302
General2
2026-07-111
Active Exploitation1
2026-08-241
Active Exploitation1
Full discourse8 posts
  • Urlyze@urlyzeio
    Active Exploitation

    🚨A URL from a weaponized Excel 🚨 📌VT Detections 2/64 🔗URL: hxxp://00030070755534/aHR0cDovLzE5Mi4yMjcuMjE5LjkyLzM1L2NjZS9nb29kdGhpbmdzZm9ybWUuaHRh.php Kill chain:📄 malicious .xls (OLE) → CVE-2017-0199 ↳ PHP redirector on 192.227.219[.]92 ↳ 302 → downloads goodthingsforme.hta (38 KB) ↳ mshta → cmd → PowerShell (-enc -nop -w hidden) ↳ wscript .js → .PIF = Donut shellcode loader (hidden in a fake .ttf) Urlyze inspects what the URL *delivers* — the file's structure & behavior — and calls it. That's the whole gap. Urlyze Report: https://app.urlyze.io/scan/189ab025-09e5-43f7-b6f2-748e4d3ac780 IOCs: • 192.227.219[.]92 • hxxp://192.227.219[.]92/35/cce/goodthingsforme[.]hta • HTA SHA256: e52af1bb74ee3f0368ec1779791328961c86c18b73e15c3ab28b422d7cbe1b14 Scan any URL free → http://app.urlyze.io #threatintel #malware #DFIR #infosec

    Post summary

    The post reports a weaponized Excel file that actively exploits CVE-2017-0199, detailing its malicious chain and indicating real‑world use.

    03023101.0K
    91 followersView on X
  • s127@dumdumcui8u
    General

    フィッシングからRemcos RAT感染までを追ってみた(CVE-2017-0199)|S127 https://zenn.dev/sak127001/articles/46d8f60dd53fce #zenn

    Post summary

    The tweet references CVE-2017-0199 in the context of a phishing‑to‑Remcos RAT infection chain but offers no technical or exploitation details.

    23055316
    28 followersView on X
  • yousukezan@yousukezan
    General

    フィッシングからRemcos RAT感染までを追ってみた(CVE-2017-0199)|S127 https://zenn.dev/sak127001/articles/46d8f60dd53fce #zenn

    Post summary

    The brief text only names the CVE and links an article; it contains no detailed technical information, PoC, or exploitation evidence.

    001952.2K
    14.9K followersView on X
  • 国立大学法人電気通信大学 情報基盤センター@itc_uec
    General

    【2026/03/04】日本語で書かれたばらまき型攻撃メール(Win/CVE-2017-0199)に関する注意喚起 https://ift.tt/9lCVLkQ

    Post summary

    The post alerts about a spam‑based email campaign targeting Windows CVE‑2017‑0199, but offers no technical or exploit details, patches, or evidence of active exploitation.

    020421.4K
    2.7K followersView on X
  • RST Cloud@rst_cloud

    #threatreport #MediumCompleteness Beware of phishing emails disguised as project material purchase request forms | 29-09-2026 Source: https://asec.ahnlab.com/ko/95596/ Key details below ↓ 💀Threats: Steganography_technique, Remcos_rat, 🔓CVEs: CVE-2017-0199 \[[Vulners](https://vulners.com/cve/CVE-2017-0199)] - CVSS V3.1: *7.8*, - Vulners: Exploitation: True Soft: - microsoft office (2007, 2010, 2013, 2016) - microsoft windows_7 (-) - microsoft windows_server_2008 (-, r2) - microsoft windows_server_2012 (-) ... 🤖LLM extracted TTPs:` T1027, T1027.003, T1036, T1041, T1047, T1056.001, T1059.001, T1082, T1105, T1113, ... 🧨IOCs: - Url: 3 - Domain: 1 - IP: 1 - Hash: 3 💽Software: Microsoft Office 🔢Algorithms: md5, base64 📜Programming Languages: powershell #threatreport: A phishing campaign distributes emails impersonating employees of a domestic company and presenting malicious XLS attachments as project materials purchase request forms. When opened, the spreadsheet displays legitimate-looking purchase request content as a decoy. The document exploits CVE-2017-0199, a Microsoft Office remote code execution vulnerability involving OLE2Link functionality. This allows the document to access an external URL and download additional payloads, including an HTA file, without relying solely on user interaction. The downloaded HTA script uses Windows Management Instrumentation (WMI), specifically the `Win32_Process.Create()` method, to execute an obfuscated PowerShell script in the background. After deobfuscation, the PowerShell script retrieves a PNG file from another command-and-control (C2) server. The image contains embedded data using steganography. The script searches for the markers `IN-` and `-inl`, extracts Base64-encoded data located between them, and processes it as a .NET loader. The extracted loader is decrypted, loaded, and executed directly in memory. It receives the address of a C2 server as an argument and uses that server to download and execute Remcos RAT. The malware can receive and execute commands remotely, collect system and user information, log keystrokes, capture screenshots, and manipulate files. It sends collected information and command execution results to external infrastructure through C2 communications. The attack chain therefore combines social engineering, exploitation of CVE-2017-0199, WMI-based execution, obfuscated PowerShell, steganographic payload concealment, in-memory .NET loading, and deployment of a remote access trojan.

    01000168
    830 followersView on X
  • truemorgan@_truemorgan
    General

    Windows: CVE-2017-0144 CVE-2017-0145 CVE-2008-4250 CVE-2019-0708 CVE-2020-1472 CVE-2021-34527 CVE-2021-26855 CVE-2020-1350 CVE-2003-0352 CVE-2014-6324 CVE-2017-0199 CVE-2021-40444 CVE-2022-30190 CVE-2021-31166 CVE-2022-21907 CVE-2019-1182 CVE-2019-1181 CVE-2020-0601 CVE-2023-29363 CVE-2023-32014 CVE-2025-24985 CVE-2025-24993 CVE-2024-38063 CVE-2022-34718 CVE-2021-26857 CVE-2021-36934 CVE-2022-37969 CVE-2022-41033 CVE-2022-38028 CVE-2023-28252 CVE-2024-26169 CVE-2025-29824 CVE-2025-30400 CVE-2025-32701 CVE-2025-32706 CVE-2016-0099 CVE-2020-1048 CVE-2017-8529 CVE-2020-0688 CVE-2021-42287 CVE-2021-42278 CVE-2022-26923 CVE-2021-34523 CVE-2021-31207 CVE-2026-32202 CVE-2017-5754 CVE-2017-5753 CVE-2018-3639 CVE-2019-11135 CVE-2018-3620

    Post summary

    The text merely enumerates a long list of Windows CVE identifiers without any further context, details, or actionable information.

    10000106
    15 followersView on X
  • Cybersecurity News Everyday@TweetThreatNews

    Phishing emails posing as project material requests trick victims into opening a malicious XLS file, triggering CVE-2017-0199, a hidden loader chain, and Remcos RAT for data theft. #CVE2017 #RemcosRAT #Korea https://www.hendryadrian.com/beware-of-phishing-emails-that-disguise-themselves-as-project-material-purchase-requests/

    00000212
    4.9K followersView on X
  • Windows Forum@windowsforum
    Active Exploitation

    🕰️ CVE-2017-0199 exploitation more than doubled in Kenya. A 2017 Office bug is still reaching users in 2026—because “patching later” remains Windows’ longest-running feature. https://windowsforum.com/windows-news.4/cve-2017-0199-exploitation-doubles-in-kenya-eset-says.443445/?utm_source=x&utm_medium=social&utm_campaign=news_node4 #WindowsSecurity #MicrosoftOffice #Cve20170199 #QrPhishing https://t.co/UNyHAEN6AX

    Post summary

    The tweet highlights a rise in exploitation of CVE‑2017‑0199 in Kenya, pointing to the persistence of an Office bug that is still affecting users years later.

    0000044
    1.3K followersView on X
CPE platform detail11 entries

11 of 11 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftoffice2007--
Appmicrosoftoffice2010--
Appmicrosoftoffice2013--
Appmicrosoftoffice2016--
OSmicrosoftwindows_7---
OSmicrosoftwindows_server_2008---
OSmicrosoftwindows_server_2008r2--
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_vista---
Appphilipsintellispace_portal7.0--
Appphilipsintellispace_portal8.0--

Explore more