cbcvebase.
CVE-2017-11826
published 2017-10-13

CVE-2017-11826: Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word Viewer, Word…

PriorityP184high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2022-03-24
Exploited in the wild
EPSS
81.45%
99.6th percentile
Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word Viewer, Word 2007, 2010, 2013 and 2016, Word Automation Services, and Office Online Server allow remote code execution when the software fails to properly handle objects in memory.

Affected

24 ranges
VendorProductVersion rangeFixed in
microsoftoffice_online_server
microsoftoffice_web_apps_server
microsoftoffice_web_apps_server
microsoftsharepoint_enterprise_server
microsoftsharepoint_server
microsoftsharepoint_server
microsoftword
microsoftword
microsoftword
microsoftword
microsoft_corporationmicrosoft_office
msrcmicrosoft_office_compatibility_pack_service_pack_3
msrcmicrosoft_office_online_server_2016
msrcmicrosoft_office_web_apps_server_2010_service_pack_2
msrcmicrosoft_office_web_apps_server_2013_service_pack_1
msrcmicrosoft_office_word_viewer
msrcmicrosoft_sharepoint_enterprise_server_2016
msrcmicrosoft_word_2007_service_pack_3
msrcmicrosoft_word_2010_service_pack_2
msrcmicrosoft_word_2013_rt_service_pack_1
msrcmicrosoft_word_2013_service_pack_1
msrcmicrosoft_word_2016
msrcword_automation_services_on_microsoft_sharepoint_server_2010_service_pack_2
msrcword_automation_services_on_microsoft_sharepoint_server_2013_service_pack_1

Detection & IOCsextracted from sources · hover to see the quote

hashcb3429e608144909ef25df2605c24ec253b10b6e99cbb6657afa6b92e9f32fb5
pathword/document.xml
yara
Exploit.MSOffice.CVE-2017-11826.a
  • For successful exploitation, an OLEObject element must appear before the malformed font tag, and the attribute name content must be at least 32 bytes after UTF-8 to Unicode conversion.
  • The exploit uses heap spraying via ActiveX components to control memory at address 0x088888EC, and bypasses ASLR/DEP using ROP gadgets from msvbvm60.dll (loaded via CLSID {D5DE8D20-5BB8-11D1-A1E3-00A0C90F2731} in the RTF \oleclsid control word).
  • The RTF exploit document contains three embedded OLE objects (\object control words). Object #1698 loads msvbvm60.dll; objects #1703 and #1708 are Word.Document.12 OLE files containing DOCX payloads (heap spray and exploit trigger respectively).
  • The heap spray DOCX (object_1703) contains a large activeX1.bin (2,099,200 bytes) and 40 activeX XML files. Presence of an unusually large activeX1.bin inside a DOCX's word/activeX/ directory is a strong indicator of this exploit.
  • Fortinet IPS signature 'MS.Office.OOXML.Parsing.Type.Confusion.Memory.Corruption' directly covers CVE-2017-11826 network-level detection.
  • ·The C2 server for the observed in-the-wild campaign was only accessible for a short period of time; dynamic analysis of the payload was limited and no C2 IP/domain was recoverable.
  • ·The detailed exploit analysis (wwlib.dll crash context, ROP chain addresses) is based specifically on wwlib.dll version 14.0.7182.5000 running on Microsoft Word 2010 32-bit; ROP gadget addresses may differ across versions.

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck7.8HIGH
cisa7.8HIGH
vendor_msrc7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.