PT-2017-3331 · Microsoft +1 · Office +2
Denis Selianin
·
Published
2017-11-14
·
Updated
2025-10-16
·
CVE-2017-11882
CVSS v2.0
9.3
9.3
High
Base vector | Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Office versions 2007 through 2016
Description
The issue is related to the improper handling of objects in memory, allowing an attacker to run arbitrary code in the context of the current user. This can be exploited by opening a specially crafted file with a vulnerable version of Microsoft Office or Microsoft WordPad. The vulnerability has been exploited in real-world incidents, including phishing attacks where attackers send emails with malicious attachments that exploit the vulnerability to download and execute malware, such as Remcos RAT. The estimated number of potentially affected devices worldwide is not specified, but it is known that the vulnerability has been used to target companies, enterprises, government agencies, and banks in various industries, including financial, logistic, and government sectors.
Recommendations
For Microsoft Office versions 2007 through 2016, apply the security patch to ensure the software is up to date. Additionally, avoid using administrator privileges when handling office documents, and consider disabling the vulnerable component until a patch is available. As a temporary workaround, restrict access to the vulnerable module to minimize the risk of exploitation.
Exploit
Fix
RCE
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
dbugs@ptsecurity.com
Weakness Enumeration
Related Identifiers
BDU:2018-00096
CVE-2017-11882
Affected Products
Office
Wordpad
Remcos Rat
References · 234
- 🔥 https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/fileformat/office_ms17_11882.rb⭐ 34266 🔗 14003 · Exploit
- 🔥 https://github.com/Ridter/CVE-2017-11882⭐ 540 🔗 252 · Exploit
- 🔥 https://github.com/embedi/CVE-2017-11882⭐ 493 🔗 183 · Exploit
- 🔥 https://github.com/unamer/CVE-2017-11882⭐ 325 🔗 95 · Exploit
- 🔥 https://github.com/rip1s/CVE-2017-11882⭐ 325 🔗 95 · Exploit
- 🔥 https://github.com/rxwx/CVE-2018-0802⭐ 271 🔗 131 · Exploit
- 🔥 https://github.com/Ridter/RTF_11882_0802⭐ 166 🔗 67 · Exploit
- 🔥 https://github.com/0x09AL/CVE-2017-11882-metasploit⭐ 98 🔗 62 · Exploit
- 🔥 https://github.com/starnightcyber/CVE-2017-11882⭐ 43 🔗 73 · Exploit
- 🔥 https://github.com/BlackMathIT/2017-11882_Generator⭐ 35 🔗 23 · Exploit
- 🔥 https://github.com/rxwx/CVE-2017-11882⭐ 42 🔗 16 · Exploit
- 🔥 https://github.com/likescam/CVE-2018-0802_CVE-2017-11882⭐ 11 🔗 5 · Exploit
- 🔥 https://github.com/likekabin/CVE-2018-0802_CVE-2017-11882⭐ 11 🔗 5 · Exploit
- 🔥 https://github.com/littlebin404/CVE-2017-11882⭐ 4 🔗 3 · Exploit
- 🔥 https://github.com/Retr0-code/SignHere⭐ 5 🔗 2 · Exploit