CVE-2018-0802Active Exploitation(microsoft / office)

HIGHCVSS 7.8 · HIGHCISA KEV

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Patch microsoft office systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts

Recommended action window: Immediate (within 24h)

NVD description

Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE is unique from CVE-2018-0797 and CVE-2018-0812.

6.3/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-05-03. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-787

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • office
  • office_compatibility_pack
  • word

Threat summary

  • Active exploitation appears in 17 classified signals
  • Exploit tooling references are present in monitored signal
  • Patch or workaround signal is available
  • 19 mentions across 11 observed days

What's happening

  • Active exploitation reported across 17 signals
  • Exploit tool or code specified in 2 signals
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 9 signals
  • Peaked 8d ago at 4 mentions (2026-02-13); latest day: 1
  • 19 total mentions across 11 days

Affected systems

Vendors
Products
officeoffice_compatibility_packword

5 versions affected across 3 products

Deep dive

Activity timeline19 mentions / 11d
01234Mentions · 2026-02-11: 1Mentions · 2026-02-12: 2Mentions · 2026-02-13: 4Mentions · 2026-02-14: 2Mentions · 2026-02-15: 2Mentions · 2026-02-16: 1Mentions · 2026-02-24: 3Mentions · 2026-02-25: 1Mentions · 2026-03-09: 1Mentions · 2026-05-22: 1Mentions · 2026-08-15: 1Exploit Tool / Code · 2026-02-16: 1Exploit Tool / Code · 2026-02-24: 1Active Exploitation · 2026-02-11: 1Active Exploitation · 2026-02-12: 2Active Exploitation · 2026-02-13: 4Active Exploitation · 2026-02-14: 2Active Exploitation · 2026-02-15: 1Active Exploitation · 2026-02-16: 1Active Exploitation · 2026-02-24: 3Active Exploitation · 2026-02-25: 1Active Exploitation · 2026-05-22: 1Active Exploitation · 2026-08-15: 1Patch / Workaround · 2026-02-12: 1Patch / Workaround · 2026-02-14: 1Patch / Workaround · 2026-02-15: 1Patch / Workaround · 2026-03-09: 1Technical Details · 2026-02-11: 1Technical Details · 2026-02-12: 2Technical Details · 2026-02-13: 1Technical Details · 2026-02-14: 1Technical Details · 2026-02-15: 2Technical Details · 2026-02-16: 1Technical Details · 2026-02-24: 102-1102-1202-1302-1402-1502-1602-2402-2503-0905-2208-15
Signal classification2 categories
Active Exploitation
1789.5%
Patch
210.5%
Referenced assets36 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-111
Active Exploitation1
2026-02-122
Active Exploitation2
2026-02-134
Active Exploitation4
2026-02-142
Active Exploitation2
2026-02-152
Active Exploitation1Patch1
2026-02-161
Active Exploitation1
2026-02-243
Active Exploitation3
2026-02-251
Active Exploitation1
2026-03-091
Patch1
2026-05-221
Active Exploitation1
2026-08-151
Active Exploitation1
Full discourse19 posts
  • kokumօtօ@__kokumoto
    Active Exploitation

    10件の脆弱性でランサムウェアによる悪用が確認された。米国サイバーセキュリティ・社会基盤安全保障庁(CISA)の既知の悪用された脆弱性が更新。対象は以下。 - CVE-2025-60710 (Windows) - CVE-2020-29574 (CyberoamOS) - CVE-2020-0618 (SQL Server) - CVE-2021-4034 (polkit) - CVE-2016-0189 (IE) - CVE-2022-21882 (Windows) - CVE-2019-5591 (FortiOS) - CVE-2019-0803 (Windows) - CVE-2018-0802 (Office) - CVE-2020-0968 (IE)

    Post summary

    CISA reports confirmed ransomware exploitation across 10 CVEs, indicating active attacks in the wild.

    01121102.7K
    7.8K followersView on X
  • Misbar | مسبار@MisbarSec
    Active Exploitation

    🚨 حملة تصيد تستغل Excel لتوزيع XWorm RAT وصلت حملة تصيد جديدة تستخدم ملفات Excel خبيثة لنشر XWorm RAT، وهو برنامج وصول عن بعد قوي. هذه الحملة تستغل ثغرة قديمة، مما يسمح للمهاجمين بالوصول إلى الأنظمة عن بعد دون ترك أثر ملفات تقليدية. التركيز على استغلال CVE-2018-0802 مع ثغرات أخرى. 💡 الحماية: * تحديث برامج Office باستمرار. * تنبيه الموظفين لفحص مرفقات Excel المشبوهة. * تفعيل خاصيات الحماية المتقدمة في برامج مكافحة الفيروسات. 🔗 https://securityonline.info/excel-trap-new-phishing-campaign-deploys-fileless-xworm-rat/ #الأمن_السيبراني #XWorm #Phishing

    Post summary

    A new phishing campaign employs malicious Excel files to deliver the XWorm RAT, exploiting CVE‑2018‑0802 and other vulnerabilities, underscoring active exploitation and urging Office updates and advanced AV protections.

    0003056
    51 followersView on X
  • ܛܔܔܔܛܔܛܔܛ@skocherhan
    Active Exploitation

    "A sophisticated phishing campaign delivering XWorm RAT has been identified. The attack chain begins with themed emails containing malicious Excel attachments exploiting CVE-2018-0802. When opened, the file downloads an HTA file, which executes PowerShell code to retrieve a fileless .NET module. This module then uses process hollowing to inject the XWorm payload into Msbuild.exe. XWorm 7.2 employs encrypted C2 communication and offers extensive features through plugins, including system control, data theft, DDoS capabilities, and ransomware functionality. The analysis reveals XWorm's modular architecture and advanced evasion techniques, highlighting it as a significant threat." 3bc1de741f8149f49bdbafa703067f24 17fc6cdd0a6959413659fec7e16cc39c 2d626765809e87696a8eeb6a0021b47d 83263d634545dd158dfa77bb011c8852 ebbcfb749a959fb53e9fc8b6dc915838 f7df418babc3917570532bf8642808bd #XWorm

    Post summary

    The post describes an active phishing campaign that exploits CVE-2018-0802 via malicious Excel attachments to deliver XWorm RAT, outlining the attack chain and techniques.

    00030166
    26.3K followersView on X
  • TechNadu@TechNadu
    Active Exploitation

    Cloud Atlas APT is targeting government & diplomatic entities in Russia and Belarus using phishing emails, CVE-2018-0802 exploits, and a new PowerCloud tool that exfiltrates data into Google Sheets. 👀 #CyberSecurity #APT #ThreatIntel #Malware #InfoSec https://t.co/WKUwAL7Eq8

    Post summary

    The tweet reports that Cloud Atlas APT is actively exploiting CVE-2018-0802 against Russian and Belarusian targets, but provides no technical details, patch info, or PoC.

    10000171
    10.1K followersView on X
  • Zeeshan Khan ⚡🜏 | InfoSec & Chaos@zeeshankghouri
    Patch

    Mitigations to steal: Patch old Office exploits (CVE-2018-0802 still chains!) Block suspicious TLDs + enable AMSI/script logging MFA + restrict app permissions Monitor for AI-tool config theft if you're in dev spaces

    Post summary

    The post advises patching the legacy Office CVE-2018-0802 and outlines general defensive measures, indicating the vulnerability remains a concern but no active exploitation is reported.

    1000029
    1.7K followersView on X
  • Machina Record@MachinaRecord
    Active Exploitation

    【リンク集:2月21日〜24日のセキュリティ関連ニュース/記事】 <脆弱性> ・BeyondTrustの脆弱性がランサムウェア攻撃に悪用される(CVE-2026-1731) https://www.securityweek.com/beyondtrust-vulnerability-exploited-in-ransomware-attacks/ ・WebメールソフトRoundCubeの脆弱性、攻撃で悪用される(CVE-2025-49113) https://www.securityweek.com/recent-roundcube-webmail-vulnerability-exploited-in-attacks/ <マルウェア・その他脅威> ・Excelの脆弱性を悪用してXWorm 7.2をJPEGファイルに隠蔽、PCをハイジャック(CVE-2018-0802) https://hackread.com/hackers-excel-exploit-xworm-7-2-jpeg-files-hijack-pcs/ ・Predatorスパイウェア、iOS SpringBoardをフックしてマイクとカメラのインジケーターを隠蔽 https://www.bleepingcomputer.com/news/security/predator-spyware-hooks-ios-springboard-to-hide-mic-camera-activity/ ・短期間で消えたArkanixスティーラー、AIを使った開発実験だった可能性 https://www.bleepingcomputer.com/news/security/arkanix-stealer-pops-up-as-short-lived-ai-info-stealer-experiment/ ・Pulsar RATをPNG画像内に隠蔽する手法、新たなnpmサプライチェーン攻撃で観測される https://hackread.com/hackers-pulsar-rat-png-images-npm-supply-chain-attack/ ・MuddyWaterが中東・北アフリカの複数組織を標的に GhostFetch・CHAR・HTTP_VIPを配信 https://thehackernews.com/2026/02/muddywater-targets-mena-organizations.html <ランサムウェア> ・ShinyHuntersがラスベガスのカジノリゾート大手を脅迫 身代金150万ドルを要求 https://www.theregister.com/2026/02/20/shinyhunters_wynn_resorts/ ・ランサムウェア攻撃の9割がファイアウォールを侵害 Barracudaが警告 https://www.scworld.com/brief/barracuda-report-firewalls-exploited-in-90-of-ransomware-incidents ・エール・コートジボワール、ランサムウェアグループの主張受けサイバー攻撃を確認 https://therecord.media/air-cote-divoire-confirms-cyberattack <データ侵害/サイバー犯罪> ・AIコーディングアシスタントClineが侵害される OpenClawを勝手にインストール https://www.theregister.com/2026/02/20/openclaw_snuck_into_cline_package/ ・AI支援型ハッカー、5週間でFortinetファイアウォール600件を侵害 Amazon報告 https://www.bleepingcomputer.com/news/security/amazon-ai-assisted-hacker-breached-600-fortigate-firewalls-in-5-weeks/ ・アドテク企業Optimizely、ビッシング攻撃後のデータ侵害を確認 https://www.bleepingcomputer.com/news/security/ad-tech-firm-optimizely-confirms-data-breach-after-vishing-attack/ ・PayPalユーザー100人分の情報が6か月間漏洩 自社システムへの侵害はなし https://www.bleepingcomputer.com/news/security/paypal-discloses-data-breach-exposing-users-personal-information/ <AI関連> ・Amazon Web Servicesが複数回ダウン 原因は自社AIコーディングボット https://arstechnica.com/ai/2026/02/an-ai-coding-bot-took-down-amazon-web-services/ ・OpenClawエージェント、受信トレイの整理を指示されると暴走を開始 Meta AIのセキュリティ研究者が報告 https://techcrunch.com/2026/02/23/a-meta-ai-security-researcher-said-an-openclaw-agent-ran-amok-on-her-inbox/ ・AIエージェントが経済を破壊する可能性 https://techcrunch.com/2026/02/23/how-ai-agents-could-destroy-the-economy/ ・自律型AIエージェントを介した新たなサプライチェーン攻撃 https://www.securityweek.com/autonomous-ai-agents-provide-new-class-of-supply-chain-attack/ <サイバー戦/APT/国家型アクター/地政学関連> ・ロシア、西側諸国との長期対立に備えハイブリッド攻撃を強化 オランダ情報機関が警告 https://therecord.media/russia-cyberattacks-europe-warfare <逮捕/テイクダウン/制裁/違反/その他法執行関連> ・ルーマニア人ハッカーが有罪認める 米オレゴン州ネットワークへの不正アクセスを販売した罪で https://www.securityweek.com/romanian-hacker-pleads-guilty-to-selling-access-to-us-state-network/ ・米司法、ウクライナ国籍の男に拘禁5年の判決 北朝鮮ITワーカーの米国企業侵入を支援した罪で https://www.bleepingcomputer.com/news/security/ukrainian-gets-5-years-for-helping-north-koreans-infiltrate-us-firms/ ・スペイン当局、Anonymousのメンバーとみられる複数人を拘束 洪水発生後のDDoS攻撃に関与した疑いで https://www.theregister.com/2026/02/23/anonymous_arrests_spain/ <リサーチ/攻撃手法/TTP> ・自己増殖可能なXMRigキャンペーン、BYOVD攻撃と時限型ロジックボムを使用 https://thehackernews.com/2026/02/wormable-xmrig-campaign-uses-byovd.html ・ClawHubに投稿された虚偽のアドバイスからインフォスティーラーに感染 https://www.helpnetsecurity.com/2026/02/23/clawhub-malicious-comment-infostealer/ <その他> ・米NIST、単一光子を生成するチップを開発 https://www.securityweek.com/nists-quantum-breakthrough-single-photons-produced-on-a-chip/ ・WikipediaがArchive[.]todayの使用を禁止 リンク69万5,000件は削除・置換へ https://arstechnica.com/tech-policy/2026/02/wikipedia-bans-archive-today-after-site-executed-ddos-and-altered-web-captures/

    Post summary

    The text reports that CVE-2026-1731 and CVE-2025-49113 are being actively exploited in ransomware and other attacks, but provides no PoC, patch, or technical details.

    00010252
    1.2K followersView on X
  • Machina Record@MachinaRecord
    Active Exploitation

    ⚠️ハッカーがExcelの脆弱性を悪用してXWorm 7.2をJPEGファイルに隠蔽、PCをハイジャック(CVE-2018-0802) 📝ランサムウェア攻撃の9割がファイアウォールを侵害 Barracudaが報告 〜サイバーセキュリティ週末の話題〜 https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/44084/

    Post summary

    The post reports that CVE‑2018‑0802 was actively exploited by hackers to embed XWorm 7.2 in JPEG files and hijack PCs, with no PoC, exploit code, patch, or technical details provided.

    00001246
    1.2K followersView on X
  • J Schmidt@BankingNeko
    Patch

    @PVynckier XWorm RAT exploiting CVE-2018-0802? Fintech security teams must act now. Patch those Excel vulnerabilities and tighten phishing defenses before attackers strike.

    Post summary

    The tweet highlights a potential XWorm RAT exploitation of CVE‑2018‑0802 and urges fintech teams to patch Excel vulnerabilities, but lacks concrete PoC or exploit details.

    0001031
    115 followersView on X
  • Dr.Philippe Vynckier, CISSP - Influencer@PVynckier
    Active Exploitation

    New XWorm RAT Campaign Leverages Phishing and CVE-2018-0802 Excel Exploit to Bypass Detection https://gbhackers.com/new-xworm-rat-campaign/

    Post summary

    The post reports a new XWorm RAT campaign that exploits CVE-2018-0802 via Excel to bypass detection, indicating ongoing real‑world attacks.

    1000073
    24.1K followersView on X
  • Cyber Edition@CyberEdition
    Active Exploitation

    XWorm via CVE-2018-0802 Excel phish: full RAT chain. https://thecyberedition.com/xworm-cve-2018-0802-phishing/ #MalwareRansomware #Cybersecurity

    Post summary

    The post announces that XWorm is actively exploiting CVE-2018-0802 via Excel phishing, presenting a full remote access tool chain.

    0000152
    666 followersView on X
  • Six Actualités - Les infos de france et du monde@SixActualitesFr
    Active Exploitation

    XWorm : Une campagne de phishing exploitant la faille CVE-2018-0802 pour déployer un RAT sans fichier - Analyse par SOC Prime https://sixactualites.fr/arnaques/xworm-une-campagne-de-phishing-exploitant-la-faille-cve-2018-0802-pour-deployer-un-rat-sans-fichier-analyse-par-soc-prime/88266/

    Post summary

    XWorm uses a phishing campaign to exploit CVE‑2018‑0802 for file‑less RAT deployment, indicating active exploitation in the wild.

    0001032
    113 followersView on X
  • タモ<ハザードマップを確認しましょう>💉x5@tamosan
    Active Exploitation

    『XWormはモジュール式を採用しているため、50種類以上のプラグインが追加できる』:Excelの古い脆弱性、XWormマルウェア配布に悪用される(CVE-2018-0802) | Codebook|Security News https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/44084/

    Post summary

    The article reports that CVE-2018-0802, an old Excel vulnerability, is being actively exploited by XWorm malware distribution, but provides no PoC, patch, or detailed technical information.

    00000135
    2.3K followersView on X
  • ThreatSynop@ThreatSynop
    Active Exploitation

    🚨 XWorm RAT Spreads via “Normal” Business Emails Using Excel Exploit + JPEG-Hidden Payload Seemingly routine business emails (payment requests/bank docs) deliver an Excel attachment that exploits CVE-2018-0802, then runs a script to download a malicious payload concealed inside a JPEG and uses process hollowing to inject XWorm into msbuild.exe for stealthy remote control. This matters because it blends old-but-reliable Office exploitation with evasive file-hiding and in-memory execution, increasing success against users who trust “mundane” workflows. 🕷️ Malware: XWorm RAT 🎯 Target: Global/Windows Users #️⃣ Category: #Malware #CyberCrime #Vulnerability 🔗 URL: https://www.scworld.com/brief/xworm-malware-campaign-leverages-mundane-emails-for-pc-infections

    Post summary

    XWorm RAT is actively exploiting CVE‑2018‑0802 via malicious Excel attachments, downloading a hidden JPEG payload and using process hollowing to inject into msbuild.exe for stealthy remote control.

    0000053
    196 followersView on X
  • ThreatSynop@ThreatSynop
    Active Exploitation

    🚨 Phishing Excel Add-ins Exploit Old Office Flaw to Deploy XWorm RAT via Fileless Chain Attackers send multilingual business-themed phishing emails with a malicious Excel add-in that exploits CVE-2018-0802 (Equation Editor RCE) to run shellcode, drop an HTA, and use PowerShell to load a Base64-encoded .NET module from a disguised image in-memory before process-hollowing msbuild.exe to inject XWorm v7.2. This matters because it shows legacy Office components still enable modern, stealthy RAT deployment with full remote control and modular plugins for theft, surveillance, DDoS, and ransomware. 🕷️ Malware: XWorm RAT 🎯 Target: Global/Windows Users #️⃣ Category: #Malware #Vulnerability #CyberIntel 🔗 URL: https://cyberpress.org/phishing-spreads-xworm-rat/

    Post summary

    The article reports that CVE‑2018‑0802 is being actively exploited via phishing emails with malicious Excel add‑ins, deploying XWorm RAT using a detailed fileless chain.

    0000044
    176 followersView on X
  • StrongKeep Cybersecurity@StrongKeepCyber
    Active Exploitation

    New phishing trend spotted: themed lures delivering XWorm RAT via CVE-2018-0802 Excel exploits. It targets Windows users with social tricks to gain remote access. Train staff, verify attachments, patch Excel, and limit macros. Read more: https://cybersecuritynews.com/new-xworm-rat-campaign-uses-themed-phishing-lures/

    Post summary

    The article reports a new phishing campaign exploiting CVE‑2018‑0802 in Excel to deliver the XWorm RAT, indicating active exploitation in the wild, and recommends staff training, attachment verification, Excel patching, and macro restrictions.

    0000023
    2 followersView on X
  • RSSFeedsCloud@RSSFeedsCloud
    Active Exploitation

    New Post: New XWorm RAT Campaign Uses Themed Phishing Lures and CVE‑2018‑0802 Excel Exploit to Evade Detection https://rssfeeds.cloudsite.builders/2026/02/13/new-xworm-rat-campaign-uses-themed-phishing-lures-and-cve-2018-0802-excel-exploit-to-evade-detection https://t.co/7FdiudZsvg

    Post summary

    The post announces an XWorm RAT campaign that is actively exploiting CVE‑2018‑0802 via themed phishing lures to evade detection.

    0000034
    504 followersView on X
  • ThreatCluster@threatcluster
    Active Exploitation

    New XWorm RAT phishing campaign exploits CVE-2018-0802 Excel flaw to gain full remote control of Windows systems, with updated variants sold on Telegram since 2022. #Malware https://threatcluster.io/cluster/xworm-rat-campaign-utilizes-phishing-and-cve-2018-0802-explo-b17beb49

    Post summary

    XWorm RAT is actively exploiting CVE‑2018‑0802 via phishing to gain full remote control of Windows systems, with updated variants distributed on Telegram since 2022.

    0000068
    79 followersView on X
  • ThreatSynop@ThreatSynop
    Active Exploitation

    🚨 New XWorm RAT phishing campaign exploits CVE-2018-0802 to go fileless and evade detection Attackers use themed business phishing emails with malicious .XLAM attachments that trigger CVE-2018-0802 (Equation Editor) to drop an HTA, run obfuscated PowerShell, load a .NET module in-memory, and process-hollow Msbuild.exe to execute XWorm with AES-encrypted C2. This matters because it blends legacy Office exploitation with fileless tradecraft, increasing hands-on-keyboard takeover risk for Windows environments. 🕷️ Malware: XWorm RAT 🎯 Target: Global/Windows users (enterprise email recipients) #️⃣ Category: #Malware #CyberCrime #TargetedAttacks 🔗 URL: https://cybersecuritynews.com/new-xworm-rat-campaign-uses-themed-phishing-lures/

    Post summary

    The article reports an ongoing phishing campaign that actively exploits CVE‑2018‑0802 to deploy the XWorm RAT via fileless, in‑memory techniques, illustrating a blend of legacy Office exploitation and modern tradecraft.

    0000043
    191 followersView on X
  • TechNadu@TechNadu
    Active Exploitation

    New XWorm v7.2 campaign analyzed. Excel (.XLAM) → CVE-2018-0802 → HTA → PowerShell → fileless .NET loader → process hollowing into Msbuild.exe. AES-encrypted C2 + 50+ plugin modules. Layered and modular. Where would you detect it first? Follow @TechNadu for technical threat breakdowns. #CyberSecurity #XWorm #Malware #ThreatIntel #Infosec #BlueTeam #DFIR #Phishing

    Post summary

    The text reports on a new XWorm campaign that actively exploits CVE‑2018‑0802, outlining a detailed exploitation chain and highlighting modular, fileless loader techniques.

    0000063
    10.0K followersView on X
CPE platform detail11 entries

11 of 11 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftoffice2007--
Appmicrosoftoffice2010--
Appmicrosoftoffice2013--
Appmicrosoftoffice2016--
Appmicrosoftoffice2016--
Appmicrosoftoffice_compatibility_pack---
Appmicrosoftword2007--
Appmicrosoftword2010--
Appmicrosoftword2013--
Appmicrosoftword2013--
Appmicrosoftword2016--

Explore more