CVE-2017-11884
published 2017-11-15CVE-2017-11884: Microsoft Excel 2016 Click-to-Run (C2R) allows an attacker to run arbitrary code in the context of the current user by failing to properly handle objects in…
PriorityP273high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
9.49%
94.9th percentile
Microsoft Excel 2016 Click-to-Run (C2R) allows an attacker to run arbitrary code in the context of the current user by failing to properly handle objects in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11882.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | excel | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft_corporation | microsoft_office | — | — |
| msrc | microsoft_excel_2016_click-to-run_for_32-bit_editions | — | — |
| msrc | microsoft_excel_2016_click-to-run_for_64-bit_editions | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Vulnerability is triggered by opening a specially crafted Microsoft Excel file; monitor for suspicious Excel file opens, especially from email attachments or web downloads. ↗
- →In email-based attack scenarios, the attacker delivers the malicious Excel file as an attachment; monitor email gateways for Excel files from untrusted senders. ↗
- →In web-based attack scenarios, attacker hosts or leverages a compromised website serving the malicious file; monitor web proxy logs for Excel file downloads from suspicious or newly registered domains. ↗
- →Affected product is Microsoft Excel 2016 Click-to-Run (C2R) only; scope detection and patching efforts to C2R installations specifically. ↗
- →This CVE is distinct from CVE-2017-11882 but shares the same vulnerability class (Office memory corruption); detections for CVE-2017-11882 may need to be evaluated separately for coverage of this CVE. ↗
- ·This security update applies to the Click-to-Run (C2R) version of Microsoft Excel 2016 only; MSI-based or other Office installations are not covered by this specific update. ↗
- ·The vulnerable component may be shared across multiple Microsoft Office products and versions beyond those explicitly listed in the Affected Products table; broader Office deployments should be assessed. ↗
- ·As of the advisory, the vulnerability had not been publicly disclosed or exploited in the wild, reducing immediate urgency but not eliminating risk. ↗
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck7.8HIGH
vendor_msrc7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cf25-5rjj-26cw: Microsoft Excel 2016 Click-to-Run (C2R) allows an attacker to run arbitrary code in the context of the current user by failing to properly handle obje
ghsa_unreviewed·2022-05-14·CVSS 7.8
CVE-2017-11884 [HIGH] CWE-119 GHSA-cf25-5rjj-26cw: Microsoft Excel 2016 Click-to-Run (C2R) allows an attacker to run arbitrary code in the context of the current user by failing to properly handle obje
Microsoft Excel 2016 Click-to-Run (C2R) allows an attacker to run arbitrary code in the context of the current user by failing to properly handle objects in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11882.
GHSA
GHSA-vjph-m3mp-rqj5: Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Microsoft Office 2016 allow an a
ghsa_unreviewed·2022-05-13·CVSS 7.8
CVE-2017-11882 [HIGH] CWE-119 GHSA-vjph-m3mp-rqj5: Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Microsoft Office 2016 allow an a
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Microsoft Office 2016 allow an attacker to run arbitrary code in the context of the current user by failing to properly handle objects in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11884.
VulnCheck
Microsoft Excel Improper Restriction of Operations within the Bounds of a Memory Buffer
vulncheck·2017·CVSS 7.8
CVE-2017-11884 [HIGH] Microsoft Excel Improper Restriction of Operations within the Bounds of a Memory Buffer
Microsoft Excel Improper Restriction of Operations within the Bounds of a Memory Buffer
Microsoft Excel 2016 Click-to-Run (C2R) allows an attacker to run arbitrary code in the context of the current user by failing to properly handle objects in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11882.
Affected: Microsoft Excel
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://bi.zone/upload/for_download/Threat_Zone_2024_BI.ZONE_Research_rus.pdf
Microsoft
Microsoft Excel Remote Code Execution Vulnerability
vendor_msrc·2017-11-14·CVSS 7.8
CVE-2017-11884 [HIGH] Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
Exploitation of the vulnerability requires that a user open a specially crafted file wit
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/101766http://www.securitytracker.com/id/1039783https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11884http://www.securityfocus.com/bid/101766http://www.securitytracker.com/id/1039783https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11884
2017-11-15
Published
Exploited in the wild