vulnti.work

Microsoft Office Remote Code Execution Vulnerability

Critical Listed in CISA KEV
CVECVE-2017-11826
First seen2022-03-03 00:00 UTC
Disclosed2022-03-03 00:00 UTC
Last updated2026-07-18 01:15 UTC
Channel statuspending_review

Summary

A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user.

In-depth triage · Auto channel

No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).

Affected products

  • Microsoft:Office

Sources

  • CISA KEV DATABASE

Original Links

Timeline

  1. kev_added CISA KEV
  2. kev_ingest CISA KEV