PT-2017-3331 · Microsoft +1 · Office +2
Denis Selianin
·
Published
2017-11-14
·
Updated
2025-11-19
·
CVE-2017-11882
CVSS v2.0
9.3
9.3
High
| Base vector | Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Office versions prior to the fixes included in the 2017 patch releases
Microsoft Office 2007 Service Pack 3
Microsoft Office 2010 Service Pack 2
Microsoft Office 2013 Service Pack 1
Microsoft Office 2016
Description
A flaw exists in Microsoft Office software due to improper handling of objects in memory. Successful exploitation of this issue allows an attacker to execute arbitrary code within the context of the current user. If the user possesses administrative privileges, the attacker could gain control of the system, enabling them to install programs, modify or delete data, and create new accounts with full user rights. The vulnerability requires a user to open a specially crafted file using a vulnerable version of Microsoft Office or Microsoft WordPad. This issue has been actively exploited for several years, with reports indicating ongoing attacks even after patches were released. The vulnerability, identified as CVE-2017-11882, has been used in phishing campaigns to deliver malware such as Agent Tesla and RemCos. Attackers have employed various techniques, including the use of malicious RTF files and exploitation of the Equation Editor component. Some threat actors, like Mysterious Elephant and Mahagrass, have leveraged this vulnerability as part of their attack chains.
Recommendations
Apply the security patches released by Microsoft in 2017 for Microsoft Office 2007 Service Pack 3.
Apply the security patches released by Microsoft in 2017 for Microsoft Office 2010 Service Pack 2.
Apply the security patches released by Microsoft in 2017 for Microsoft Office 2013 Service Pack 1.
Apply the security patches released by Microsoft in 2017 for Microsoft Office 2016.
Exploit
Fix
RCE
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
dbugs@ptsecurity.com
Weakness Enumeration
Related Identifiers
BDU:2018-00096
CVE-2017-11882
Affected Products
Office
Wordpad
Remcos Rat
References · 242
- 🔥 https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/fileformat/office_ms17_11882.rb⭐ 34266 🔗 14003 · Exploit
- 🔥 https://github.com/Ridter/CVE-2017-11882⭐ 540 🔗 252 · Exploit
- 🔥 https://github.com/embedi/CVE-2017-11882⭐ 493 🔗 183 · Exploit
- 🔥 https://github.com/rip1s/CVE-2017-11882⭐ 325 🔗 95 · Exploit
- 🔥 https://github.com/unamer/CVE-2017-11882⭐ 325 🔗 95 · Exploit
- 🔥 https://github.com/rxwx/CVE-2018-0802⭐ 271 🔗 131 · Exploit
- 🔥 https://github.com/Ridter/RTF_11882_0802⭐ 166 🔗 67 · Exploit
- 🔥 https://github.com/0x09AL/CVE-2017-11882-metasploit⭐ 98 🔗 62 · Exploit
- 🔥 https://github.com/starnightcyber/CVE-2017-11882⭐ 43 🔗 73 · Exploit
- 🔥 https://github.com/BlackMathIT/2017-11882_Generator⭐ 35 🔗 23 · Exploit
- 🔥 https://github.com/rxwx/CVE-2017-11882⭐ 42 🔗 16 · Exploit
- 🔥 https://github.com/likekabin/CVE-2018-0802_CVE-2017-11882⭐ 11 🔗 5 · Exploit
- 🔥 https://github.com/likescam/CVE-2018-0802_CVE-2017-11882⭐ 11 🔗 5 · Exploit
- 🔥 https://github.com/littlebin404/CVE-2017-11882⭐ 4 🔗 3 · Exploit
- 🔥 https://github.com/Retr0-code/SignHere⭐ 5 🔗 2 · Exploit