CVE-2017-11882General(microsoft / office)

MEDIUMCVSS 7.8 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch microsoft office systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Microsoft Office 2016 allow an attacker to run arbitrary code in the context of the current user by failing to properly handle objects in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11884.

5.8/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-05-03. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-119

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • office

Threat summary

  • Active exploitation appears in 3 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 9 mentions across 9 observed days

What's happening

  • Active exploitation reported across 3 signals
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • General: 4 classified signals
  • Disclosure: 2 classified signals
  • Peaked 8d ago at 1 mentions (2026-02-02); latest day: 1
  • 9 total mentions across 9 days

Affected systems

Vendors
Products
office

4 versions affected across 1 product

Deep dive

Activity timeline9 mentions / 9d
00111Mentions · 2026-02-02: 1Mentions · 2026-02-18: 1Mentions · 2026-02-23: 1Mentions · 2026-02-24: 1Mentions · 2026-04-17: 1Mentions · 2026-06-04: 1Mentions · 2026-06-05: 1Mentions · 2026-06-08: 1Mentions · 2026-06-13: 1PoC Mentioned / Linked · 2026-06-04: 1PoC Mentioned / Linked · 2026-06-13: 1Active Exploitation · 2026-02-18: 1Active Exploitation · 2026-04-17: 1Active Exploitation · 2026-06-08: 1Patch / Workaround · 2026-04-17: 1Technical Details · 2026-02-18: 1Technical Details · 2026-02-23: 1Technical Details · 2026-06-08: 102-0202-1802-2302-2404-1706-0406-0506-0806-13
Signal classification3 categories
General
444.4%
Active Exploitation
333.3%
Disclosure
222.2%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-021
General1
2026-02-181
Active Exploitation1
2026-02-231
Disclosure1
2026-02-241
General1
2026-04-171
Active Exploitation1
2026-06-041
Disclosure1
2026-06-051
General1
2026-06-081
Active Exploitation1
2026-06-131
General1
Full discourse9 posts
  • Karsten Hahn@struppigel
    Disclosure

    .@_hwangstice did a detailed writeup how the equation editor exploit CVE-2017-11882 works. https://hwangstice.github.io/blog/rtf-document/ https://t.co/guqglw57ZU

    Post summary

    The tweet links to a blog post that details how the Equation Editor CVE-2017-11882 works, likely including a PoC, but it provides no evidence of active exploitation, patches, or debunking.

    018036184.0K
    25.9K followersView on X
  • ܛܔܔܔܛܔܛܔܛ@skocherhan
    General

    2f9ea08bda2902fd783534037b48ca13 7e94fbb8330f2a994eb2f707aac45c14 mismilahioluwadoam[.]duckdns[.]org 107[.]174[.]34[.]163:14643 107[.]174[.]33[.]21 AS36352 COLOCROSSING 🇺🇸 cve-2017-11882 cve-2008-3021 cve-2008-3018 #Remcos @JAMESWT_WT https://t.co/LUY5uTSp3B

    Post summary

    The content lists several CVE identifiers along with unrelated IP addresses and a domain, but provides no additional context, exploitation details, or mitigation information.

    02062808
    26.3K followersView on X
  • Umid Mammadov@umidcybers
    Disclosure

    How does a 20-year-old Office template bypass modern defenses? I tore apart the "Tax Invoice" anonim.xls malware (CVE-2017-11882) in the lab: 🔥 In-memory payload unpacking (Ghidra) 🔥 LotL & UAC Bypass via slui.exe 🔥 C2 traffic hidden on port 8836 https://medium.com/@umidcybers/deep-dive-the-dark-architecture-behind-fake-invoices-and-the-cve-2017-11882-exploitation-6ec14ee64b77 https://t.co/cJC7GRTHRi

    Post summary

    Lab analysis of CVE‑2017‑11882 shows in‑memory unpacking, UAC bypass via slui.exe, and hidden C2 traffic on port 8836, but no active exploitation or patch information is provided.

    00040244
    61 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-45247 2 - CVE-2026-27914 3 - CVE-2017-11882 4 - CVE-2026-45495 5 - CVE-2026-0826 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    A brief tweet listing five trending CVEs without providing any technical details, fixes, or exploit information.

    0002099
    1.7K followersView on X
  • ThreatCluster@threatcluster
    Active Exploitation

    MITRE ATT&CK reports that APT28 has repeatedly exploited Microsoft Office flaws CVE-2012-0158 and CVE-2017-11882 via malicious documents to gain remote code execution on victim systems. https://threatcluster.io/cluster/exploitation-of-client-software-vulnerabilities-and-user-exe-be78ab56

    Post summary

    The post highlights that APT28 is actively exploiting Microsoft Office CVE‑2012‑0158 and CVE‑2017‑11882, achieving remote code execution through malicious documents.

    0100062
    317 followersView on X
  • Felix Kiprop@KipropFelix48
    General

    @vxunderground I received a doc containing "CVE-2017-11882" as exploit. does it qualify to be a cat pic?? some AV din't flag it. https://t.co/eKSRQQBZOq

    Post summary

    The post references a document containing an exploit for CVE‑2017‑11882 but lacks evidence of active attacks, detailed technical info, or patching guidance.

    00000311
    59 followersView on X
  • The Daily Tech Feed@dailytechonx
    Active Exploitation

    A 17-year-old Excel vulnerability, CVE-2017-11882, is still being exploited to spread malware like Agent Tesla. Ensure your systems are patched and stay vigilant. Link: https://thedailytechfeed.com/17-year-old-microsoft-excel-flaw-still-exploited-by-cybercriminals-highlights-persistent-security-risks/ #Vulnerability #Malware #Security #Cybercrime #Threat #Patch #Microsoft #Excel #Exploit #AgentTesla #Protection #Awareness #Hacking #Data #Risks #Spyware #Breach #Safety #Phishing #Cyberattack

    Post summary

    CVE-2017-11882 remains actively exploited by cybercriminals using Agent Tesla; users are urged to patch and remain vigilant.

    000004
    279 followersView on X
  • ‘BugBounty Writeups’@bbwriteups
    General

    "DEEP DIVE: The Dark Architecture Behind Fake Invoices and the CVE-2017–11882 Exploitation" by Umid Mammadov #BugBounty #Cybersecurity #Hacking #InfoSec https://medium.com/@umidcybers/deep-dive-the-dark-architecture-behind-fake-invoices-and-the-cve-2017-11882-exploitation-6ec14ee64b77

    Post summary

    The provided text is a title and link to a Medium article about CVE-2017‑11882, but it contains no specific technical, exploit, or patch information.

    0000054
    485 followersView on X
  • ThreatSynop@ThreatSynop
    Active Exploitation

    🚨 Malware Campaign Reuses “PNG/JPEG Base64 Payload” Trick to Hide .NET Loader Behind Office Exploit A new campaign delivers a weaponized XLS attachment exploiting Equation Editor (CVE-2017-11882) to fetch an HTA → PowerShell chain that downloads a “.png” file containing a Base64-encoded next-stage payload between “BaseStart-/-BaseEnd” tags, ultimately dropping an unnamed .NET binary. The reuse of the exact same image across many samples suggests a shared toolkit/infrastructure, enabling defenders to track activity via VT similarity hunting and YARA matching. (unnamed .NET payload/loader) 🎯 Target: Global/Windows (Microsoft Office users) #️⃣ Category: #Malware #CyberIntel 🔗 URL: https://isc.sans.edu/diary/rss/32726

    Post summary

    The article reports a new malware campaign that weaponizes CVE-2017-11882 via a weaponized XLS attachment, using an HTA → PowerShell chain to download a Base64‑encoded .NET payload hidden in a PNG file, and advises tracking via VT similarity and YARA.

    0000036
    176 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftoffice2007--
Appmicrosoftoffice2010--
Appmicrosoftoffice2013--
Appmicrosoftoffice2016--

Explore more