CVE-2017-11826 is a critical remote code execution vulnerability affecting numerous Microsoft Office and SharePoint products, including various versions of Word and Office Web Apps. This high-severity flaw, with a CVSS score of 7.8, allows attackers to execute arbitrary code when the software improperly handles objects in memory, requiring user interaction (e.g., opening a malicious document) for exploitation. The vulnerability has been actively exploited in the wild, as indicated by its presence in the KEV catalog and significant media coverage, despite a lack of public exploit code in common repositories like Metasploit or ExploitDB. Its high EPSS score and extensive community discussion highlight the widespread concern and potential impact of this flaw.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:office_compatibility_pack:-:sp3:*:*:*:*:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:office_online_server:2016:*:*:*:*:*:*:* | ||
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:office_web_apps_server:2010:sp2:*:*:*:*:*:* | ||
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:office_web_apps_server:2013:sp1:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:office_word_viewer:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.