CVE-2017-0199 is a remote code execution vulnerability affecting multiple versions of Microsoft Office and Windows operating systems caused by the improper handling of OLE objects within crafted documents. With a High CVSS score of 7.8, this flaw allows remote attackers to execute arbitrary code if a user is tricked into opening a malicious file, resulting in a potential complete compromise of system confidentiality, integrity, and availability. The vulnerability poses a critical risk and is actively exploited in the wild by advanced persistent threat (APT) groups, such as BlueNoroff and Gamaredon, to deploy payloads like Cobalt Strike and FormBook. Public exploit code is widely available through frameworks like Metasploit, and the flaw remains a significant threat in current attack landscapes, as evidenced by its inclusion in the CISA Known Exploited Vulnerabilities catalog and ongoing reports of its use in 2025.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2007CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2007:sp3:*:*:*:*:*:* | ||
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2010:sp2:*:*:*:*:*:* | ||
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2013:sp1:*:*:*:*:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2016:-:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.