← All CVEs

CVE-2017-11826

high · 7.8Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions.

Added 2022-03-03Remediation due 2022-03-24

Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word Viewer, Word 2007, 2010, 2013 and 2016, Word Automation Services, and Office Online Server allow remote code execution when the software fails to properly handle objects in memory.

7.8
CVSS
81.2%
EPSS (exploit prob.)
100th
EPSS percentile
2017-10-13
Published

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Weaknesses

CWE-119

Affected products

VendorProductAffected versions
microsoftoffice_compatibility_packall versions
microsoftoffice_online_server2016
microsoftoffice_web_apps_server2010
microsoftoffice_web_apps_server2013
microsoftoffice_word_viewerall versions
microsoftsharepoint_enterprise_server2016
microsoftsharepoint_server2010
microsoftsharepoint_server2013
microsoftword2007
microsoftword2010
microsoftword2013
microsoftword2013
microsoftword2016

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2017-11826