CVE-2017-118822Active Exploitation

HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

7.0/ 10 priority

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

NONE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-12: 1PoC Mentioned / Linked · 2026-03-12: 1Exploit Tool / Code · 2026-03-12: 1Active Exploitation · 2026-03-12: 1Technical Details · 2026-03-12: 103-12
Signal classification1 categories
Active Exploitation
1100.0%
Full discourse1 post
  • ☩MalwareMustDie@malwaremustdie
    Active Exploitation

    These are stagers used by adversaries embedded in (docx/rtf/xml) to exploit cve-2017-118822 w/overflowing buffer for font at EQEDIT, stuff that they don't change easily, so use this info to recognize this #malware threat & campaign in the future. I attached here my static analysis for stager 1 and stager2 #shellcode they use. #MalwareMustDie! thanks @trufae for r2shell I use for this case! <3

    Post summary

    Adversaries are embedding stagers in Office documents to exploit CVE‑2017‑118822 by overflowing a buffer in EQEDIT; the author provides static analysis of the shellcode and references an exploitation tool, indicating documented active exploitation.

    12021352
    5.8K followersView on X

Explore more