CVE-2017-11826
published 2017-10-13CVE-2017-11826: Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word Viewer, Word…
PriorityP184high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2022-03-24
Exploited in the wild
EPSS
81.45%
99.6th percentile
Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word Viewer, Word 2007, 2010, 2013 and 2016, Word Automation Services, and Office Online Server allow remote code execution when the software fails to properly handle objects in memory.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | office_online_server | — | — |
| microsoft | office_web_apps_server | — | — |
| microsoft | office_web_apps_server | — | — |
| microsoft | sharepoint_enterprise_server | — | — |
| microsoft | sharepoint_server | — | — |
| microsoft | sharepoint_server | — | — |
| microsoft | word | — | — |
| microsoft | word | — | — |
| microsoft | word | — | — |
| microsoft | word | — | — |
| microsoft_corporation | microsoft_office | — | — |
| msrc | microsoft_office_compatibility_pack_service_pack_3 | — | — |
| msrc | microsoft_office_online_server_2016 | — | — |
| msrc | microsoft_office_web_apps_server_2010_service_pack_2 | — | — |
| msrc | microsoft_office_web_apps_server_2013_service_pack_1 | — | — |
| msrc | microsoft_office_word_viewer | — | — |
| msrc | microsoft_sharepoint_enterprise_server_2016 | — | — |
| msrc | microsoft_word_2007_service_pack_3 | — | — |
| msrc | microsoft_word_2010_service_pack_2 | — | — |
| msrc | microsoft_word_2013_rt_service_pack_1 | — | — |
| msrc | microsoft_word_2013_service_pack_1 | — | — |
| msrc | microsoft_word_2016 | — | — |
| msrc | word_automation_services_on_microsoft_sharepoint_server_2010_service_pack_2 | — | — |
| msrc | word_automation_services_on_microsoft_sharepoint_server_2013_service_pack_1 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
yara↗
Exploit.MSOffice.CVE-2017-11826.a
- →For successful exploitation, an OLEObject element must appear before the malformed font tag, and the attribute name content must be at least 32 bytes after UTF-8 to Unicode conversion. ↗
- →The exploit uses heap spraying via ActiveX components to control memory at address 0x088888EC, and bypasses ASLR/DEP using ROP gadgets from msvbvm60.dll (loaded via CLSID {D5DE8D20-5BB8-11D1-A1E3-00A0C90F2731} in the RTF \oleclsid control word). ↗
- →The RTF exploit document contains three embedded OLE objects (\object control words). Object #1698 loads msvbvm60.dll; objects #1703 and #1708 are Word.Document.12 OLE files containing DOCX payloads (heap spray and exploit trigger respectively). ↗
- →The heap spray DOCX (object_1703) contains a large activeX1.bin (2,099,200 bytes) and 40 activeX XML files. Presence of an unusually large activeX1.bin inside a DOCX's word/activeX/ directory is a strong indicator of this exploit. ↗
- →Fortinet IPS signature 'MS.Office.OOXML.Parsing.Type.Confusion.Memory.Corruption' directly covers CVE-2017-11826 network-level detection. ↗
- ·The C2 server for the observed in-the-wild campaign was only accessible for a short period of time; dynamic analysis of the payload was limited and no C2 IP/domain was recoverable. ↗
- ·The detailed exploit analysis (wwlib.dll crash context, ROP chain addresses) is based specifically on wwlib.dll version 14.0.7182.5000 running on Microsoft Word 2010 32-bit; ROP gadget addresses may differ across versions. ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck7.8HIGH
cisa7.8HIGH
vendor_msrc7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Microsoft Office Remote Code Execution Vulnerability
cisa·2022-03-03·CVSS 7.8
CVE-2017-11826 [HIGH] CWE-119 Microsoft Office Remote Code Execution Vulnerability
Vulnerability: Microsoft Office Remote Code Execution Vulnerability
Affected: Microsoft Office
A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2017-11826
Remediation Due Date: 2022-03-24
Microsoft
Microsoft Office Remote Code Execution Vulnerability
vendor_msrc·2017-10-10·CVSS 7.8
CVE-2017-11826 [HIGH] Microsoft Office Remote Code Execution Vulnerability
Microsoft Office Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
Exploitation of the vulnerability requires that a user open a specially crafted file w
GHSA
GHSA-4qcg-gx82-4h36: Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word Viewer,
ghsa_unreviewed·2022-05-17
CVE-2017-11826 [HIGH] CWE-119 GHSA-4qcg-gx82-4h36: Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word Viewer,
Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word Viewer, Word 2007, 2010, 2013 and 2016, Word Automation Services, and Office Online Server allow remote code execution when the software fails to properly handle objects in memory.
VulnCheck
Microsoft Office Remote Code Execution Vulnerability
vulncheck·2017·CVSS 7.8
CVE-2017-11826 [HIGH] CWE-119 Microsoft Office Remote Code Execution Vulnerability
Microsoft Office Remote Code Execution Vulnerability
A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user.
Affected: Microsoft Office
Required Action: Apply updates per vendor instructions.
Exploitation References: https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2017-Oct; https://www.fortinet.com/blog/threat-research/cve-2017-11826-exploited-in-the-wild-with-politically-themed-rtf-document; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Exploit PoC: https://vulnchec
No detection rules found.
No public exploits indexed.
Fortinet
Prevalent Threats Targeting Cuckoo Sandbox Detection and Our Mitigation
blogs_fortinet·2018-01-03
Prevalent Threats Targeting Cuckoo Sandbox Detection and Our Mitigation
FORTIGUARD LABS THREAT RESEARCH
Prevalent Threats Targeting Cuckoo Sandbox Detection and Our Mitigation
By Floser Bacurio and Wayne Low | January 03, 2018
Introduction
An Application Programming Interface (API) is a set of function definitions and subroutines that enable application software to interact with the underlying operating system. These function definitions are commonly monitored by security and monitoring software, such as Anti-Virus, in order to understand and evaluate the behavior of executable programs running on the target machine. Generally, behavioral monitoring can be done in a variety of ways, with one of the most widely used approaches being the API hook.
For the sake of simplicity and stability, many behavior analysis systems, such as malware analysis sandboxes, lev
Fortinet
Cobalt Malware Strikes Using CVE-2017-11882 RTF Vulnerability
blogs_fortinet·2017-11-27·CVSS 7.8
CVE-2017-11882 [HIGH] Cobalt Malware Strikes Using CVE-2017-11882 RTF Vulnerability
FORTIGUARD LABS THREAT RESEARCH
Cobalt Malware Strikes Using CVE-2017-11882 RTF Vulnerability
By Jasper Manual and Joie Salvio | November 27, 2017
Only a few days after FortiGuard Labs published an article about a spam campaign exploiting an RTF document, our Kadena Threat Intelligence System (KTIS) has found another spam campaign using an even more recent document vulnerability, CVE-2017-11882. Although the vulnerability has existed for 17 years, according to a report by SecurityWeek, it was only disclosed and patched by Microsoft in the second week of this month.
And as we have repeatedly seen, not long after its disclosure threat actors were quick to take advantage of this vulnerability to deliver a malware using a component from a well-known penetration testing tool, Cobalt Strike.
Fortinet
CVE-2017-11826 Exploited in the Wild with Politically Themed RTF Document
blogs_fortinet·2017-11-22·CVSS 7.8
CVE-2017-11826 [HIGH] CVE-2017-11826 Exploited in the Wild with Politically Themed RTF Document
FORTIGUARD LABS THREAT RESEARCH
CVE-2017-11826 Exploited in the Wild with Politically Themed RTF Document
By Jasper Manuel, Joie Salvio and Wayne Low | November 22, 2017
Recently, FortiGuard Labs found an interesting malware campaign using the recently documented vulnerability CVE-2017-11826 that was patched by Microsoft in October of this year. A detailed analysis of this exploit is also included in this article.
Based on the context of the campaign used to lure victims, as well as how the payload malware behaves, we had a hunch that this was not a common cybercrime campaign and was even possibly a targeted attack on specific institutions or locales. For this reason, we decided to look deeper.
As is common with this type of attack, the command-and-control (C2) server for this campaign
Fortinet
Cybercriminals Exploiting Microsoft’s Vulnerable Dynamic Data Exchange Protocol
blogs_fortinet·2017-11-17·CVSS 8.8
[HIGH] Cybercriminals Exploiting Microsoft’s Vulnerable Dynamic Data Exchange Protocol
FORTIGUARD LABS THREAT RESEARCH
Cybercriminals Exploiting Microsoft’s Vulnerable Dynamic Data Exchange Protocol
By FortiGuard SE Team | November 17, 2017
Visa Payment Systems Intelligence recently announced that cybercriminals are threatening the payments ecosystem by leveraging a vulnerable Microsoft Dynamic Data Exchange protocol in phishing campaigns. This phishing attack relies on the Dynamic Data Exchange (DDE) protocol for infection instead of the usual malicious macros or an exploit kit.
This exploit is related to the Microsoft Security Advisory 4053440 issued on November 8, 2017. It provides guidance on securing Microsoft applications when processing Dynamic Data Exchange (DDE) fields. The DDE protocol enables messages to be sent between Microsoft applications and uses shared da
Securelist
Analyzing an exploit for СVE-2017-11826
blogs_securelist·2017-10-26
Analyzing an exploit for СVE-2017-11826
Authors
Boris Larin
The latest Patch Tuesday (17 October) brought patches for 62 vulnerabilities, including one that fixed СVE-2017-11826 – a critical zero-day vulnerability used to launch targeted attacks – in all versions of Microsoft Office.
The exploit for this vulnerability is an RTF document containing a DOCX document that exploits СVE-2017-11826 in the Office Open XML parser.
The exploit itself is in word/document.xml as follows:
Under the ECMA-376 standard for Office Open XML File Formats, the valid ‘font’ element describing the fonts used in the document must look like this:
In the body of the exploit the closing tag is absent. The opening tag is followed by the object element which cause ‘type confusion’ in the OOXML parser. Any object element can be used to successfully ex
Securelist
Analyzing an exploit for СVE-2017-11826
blogs_securelist·2017-10-26
Analyzing an exploit for СVE-2017-11826
Authors
- Boris Larin
The latest Patch Tuesday (17 October) brought patches for 62 vulnerabilities, including one that fixed СVE-2017-11826 – a critical zero-day vulnerability used to launch targeted attacks – in all versions of Microsoft Office.
The exploit for this vulnerability is an RTF document containing a DOCX document that exploits СVE-2017-11826 in the Office Open XML parser.
The exploit itself is in word/document.xml as follows:
Under the ECMA-376 standard for Office Open XML File Formats, the valid ‘font’ element describing the fonts used in the document must look like this:
In the body of the exploit the closing tag is absent. The opening tag is followed by the object element which cause ‘type confusion’ in the OOXML parser. Any object element can be used to successfully
Krebs
Microsoft’s October Patch Batch Fixes 62 Flaws
blogs_krebs·2017-10-11·CVSS 7.5
[HIGH] Microsoft’s October Patch Batch Fixes 62 Flaws
Microsoft on Tuesday released software updates to fix at least 62 security vulnerabilities in Windows , Office and other software. Two of those flaws were detailed publicly before yesterday’s patches were released, and one of them is already being exploited in active attacks, so attackers already have a head start.
Roughly half of the flaws Microsoft addressed this week are in the code that makes up various versions of Windows, and 28 of them were labeled “critical” — meaning malware or malicious attackers could use the weaknesses to break into Windows computers remotely with no help from users.
One of the publicly disclosed Windows flaws ( CVE-2017-8703 ) fixed in this batch is a problem with a feature only present in Windows 10 known as the Windows Subsystem for Linux , which allows Wi
Krebs
Microsoft’s October Patch Batch Fixes 62 Flaws
blogs_krebs·2017-10-11·CVSS 7.5
CVE-2017-8703 [HIGH] Microsoft’s October Patch Batch Fixes 62 Flaws
Microsoft on Tuesday released software updates to fix at least 62 security vulnerabilities in Windows, Office and other software. Two of those flaws were detailed publicly before yesterday’s patches were released, and one of them is already being exploited in active attacks, so attackers already have a head start.
One of the publicly disclosed Windows flaws (CVE-2017-8703) fixed in this batch is a problem with a feature only present in Windows 10 known as the Windows Subsystem for Linux, which allows Windows 10 users to run unmodified Linux binary files. Researchers at CheckPoint recently released some interesting research worth reading about how attackers might soon use this capability to bypass antivirus and other security solutions on Windows.
The bug quashed this week that’s being ac
Qualys
October Patch Tuesday: 28 Critical Microsoft Vulnerabilities | Qualys
blogs_qualys·2017-10-10·CVSS 8.8
CVE-2017-11826 [HIGH] October Patch Tuesday: 28 Critical Microsoft Vulnerabilities | Qualys
Today Microsoft released patches covering 62 vulnerabilities as part of October’s Patch Tuesday update, with 30 of them affecting Windows. Patches covering 28 of these vulnerabilities are labeled as Critical, and 33 can result in Remote Code Execution. According to Microsoft, a vulnerability in Microsoft Office is being actively exploited in the wild.
Top priority for patching should go to a vulnerability in Microsoft Office, CVE-2017-11826, which Microsoft has ranked as “Important” and is actively being exploited in the wild.
Priority should also be given to CVE-2017-11771, which is a vulnerability in the Windows Search service. This is the fourth Patch Tuesday this year to feature a vulnerability in this service. As with the others, this vulnerability can be exploited remotely via SMB
Qualys
October Patch Tuesday: 28 Critical Microsoft Vulnerabilities
blogs_qualys·2017-10-10·CVSS 8.8
CVE-2017-11826 [HIGH] October Patch Tuesday: 28 Critical Microsoft Vulnerabilities
Today Microsoft released patches covering 62 vulnerabilities as part of October’s Patch Tuesday update, with 30 of them affecting Windows. Patches covering 28 of these vulnerabilities are labeled as Critical, and 33 can result in Remote Code Execution. According to Microsoft, a vulnerability in Microsoft Office is being actively exploited in the wild.
Top priority for patching should go to a vulnerability in Microsoft Office, CVE-2017-11826 , which Microsoft has ranked as “Important” and is actively being exploited in the wild.
Priority should also be given to CVE-2017-11771 , which is a vulnerability in the Windows Search service. This is the fourth Patch Tuesday this year to feature a vulnerability in this service. As with the others, this vulnerability can be exploited remotely via SM
Talos
Microsoft Patch Tuesday - October 2017
blogs_talos·2017-10-10·CVSS 8.8
[HIGH] Microsoft Patch Tuesday - October 2017
Microsoft has released its monthly set of security advisories for vulnerabilities that have been identified and addressed in various products. This month's advisory release addresses 63 new vulnerabilities with 28 of them rated critical and 35 rated important. These vulnerabilities impact Graphics, Edge, Internet Explorer, Office, Sharepoint, Windows Graphic Display Interface, Windows Kernel Mode Drivers, and more.
## Vulnerabilities Rated CriticalThe following vulnerabilities are rated "Critical" by Microsoft:
- CVE-2017-11813 - Internet Explorer Memory Corruption Vulnerability
- CVE-2017-11822 - Internet Explorer Memory Corruption Vulnerability
- CVE-2017-11762 - Microsoft Graphics Remote Code Execution Vulnerability
- CVE-2017-11763 - Microsoft Graphics Remote Code Execution Vulnerabi
Fortinet
Rehashed RAT Used in APT Campaign Against Vietnamese Organizations
blogs_fortinet·2017-09-05·CVSS 8.8
CVE-2012-0158 [HIGH] Rehashed RAT Used in APT Campaign Against Vietnamese Organizations
FORTIGUARD LABS THREAT RESEARCH
Rehashed RAT Used in APT Campaign Against Vietnamese Organizations
By Jasper Manuel and Artem Semenchenko | September 05, 2017
Recently, FortiGuard Labs came across several malicious documents that exploit the vulnerability CVE-2012-0158. To evade suspicion from the victim, these RTF files drop decoy documents containing politically themed texts about a variety of Vietnamese government-related information. It was believed in a recent report that the hacking campaign where these documents were used was led by the Chinese hacking group 1937CN. The link to the group was found through malicious domains used as command and control servers by the attacker. In this blog, we will delve into the malware used in this campaign and will try to provide more clues as to
Fortinet
Wrap-up: US Campaign-themed Malware and Trolls
blogs_fortinet·2016-11-15
Wrap-up: US Campaign-themed Malware and Trolls
FORTIGUARD LABS THREAT RESEARCH
Wrap-up: US Campaign-themed Malware and Trolls
By Joie Salvio and Rommel Joven | November 15, 2016
The US political season is over and a new President has been elected. This election has arguably been one of the most colorful (some might say entertaining) and controversial presidential election cycles in the country’s history. For cyber crooks, this has been just the right environment to target victims with their attacks and trolls.
In this post we take a look at some of the more notable US campaign-themed malware and scams. While some may induce false fears and a few laughs, others represent serious threats.
“Donald Trump Ransomware”
Although the author of this malware claims it is ransomware, that’s not entirely true - in its current version at least.
arXiv
Analysis and Correlation of Visual Evidence in Campaigns of Malicious Office Documents
arxiv_fulltext·2021-03-30
Analysis and Correlation of Visual Evidence in Campaigns of Malicious Office Documents
Analysis and Correlation of Visual Evidence in Campaigns of Malicious Office Documents
[1,2]Fran Casino
[3]Nikolaos Totosis
[1]Theodoros Apostolopoulos
[1]Department of Informatics, University Piraeus, 80 Karaoli & Dimitriou str, 18534 Piraeus, Greece
[1]Nikolaos Lykousas
[1,2]Constantinos Patsakis
[2]Information Management Systems Institute of Athena Research Center, Greece
[3]Hatching, Netherlands
## Abstract
Many malware campaigns use Microsoft (MS) Office documents as droppers to download and execute their malicious payload. Such campaigns often use these documents because MS Office is installed in billions of devices and that these files allow the execution of arbitrary VBA code. Recent versions of MS Office prevent the automatic execution of VBA macros, so malware authors try to co
http://www.securityfocus.com/bid/101219http://www.securitytracker.com/id/1039541https://0patch.blogspot.com/2017/11/0patching-pretty-nasty-microsoft-word.htmlhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11826https://securingtomorrow.mcafee.com/mcafee-labs/analyzing-microsoft-office-zero-day-exploit-cve-2017-11826-memory-corruption-vulnerability/https://www.tarlogic.com/en/blog/exploiting-word-cve-2017-11826/http://www.securityfocus.com/bid/101219http://www.securitytracker.com/id/1039541https://0patch.blogspot.com/2017/11/0patching-pretty-nasty-microsoft-word.htmlhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11826https://securingtomorrow.mcafee.com/mcafee-labs/analyzing-microsoft-office-zero-day-exploit-cve-2017-11826-memory-corruption-vulnerability/https://www.tarlogic.com/en/blog/exploiting-word-cve-2017-11826/https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-11826
2017-10-13
Published
2022-03-03
Added to CISA KEV
Exploited in the wild