cbcvebase.
CVE-2017-11884
published 2017-11-15

CVE-2017-11884: Microsoft Excel 2016 Click-to-Run (C2R) allows an attacker to run arbitrary code in the context of the current user by failing to properly handle objects in…

PriorityP273high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
9.49%
94.9th percentile
Microsoft Excel 2016 Click-to-Run (C2R) allows an attacker to run arbitrary code in the context of the current user by failing to properly handle objects in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11882.

Affected

8 ranges
VendorProductVersion rangeFixed in
microsoftexcel
microsoftoffice
microsoftoffice
microsoftoffice
microsoftoffice
microsoft_corporationmicrosoft_office
msrcmicrosoft_excel_2016_click-to-run_for_32-bit_editions
msrcmicrosoft_excel_2016_click-to-run_for_64-bit_editions

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability is triggered by opening a specially crafted Microsoft Excel file; monitor for suspicious Excel file opens, especially from email attachments or web downloads.
  • In email-based attack scenarios, the attacker delivers the malicious Excel file as an attachment; monitor email gateways for Excel files from untrusted senders.
  • In web-based attack scenarios, attacker hosts or leverages a compromised website serving the malicious file; monitor web proxy logs for Excel file downloads from suspicious or newly registered domains.
  • Affected product is Microsoft Excel 2016 Click-to-Run (C2R) only; scope detection and patching efforts to C2R installations specifically.
  • This CVE is distinct from CVE-2017-11882 but shares the same vulnerability class (Office memory corruption); detections for CVE-2017-11882 may need to be evaluated separately for coverage of this CVE.
  • ·This security update applies to the Click-to-Run (C2R) version of Microsoft Excel 2016 only; MSI-based or other Office installations are not covered by this specific update.
  • ·The vulnerable component may be shared across multiple Microsoft Office products and versions beyond those explicitly listed in the Affected Products table; broader Office deployments should be assessed.
  • ·As of the advisory, the vulnerability had not been publicly disclosed or exploited in the wild, reducing immediate urgency but not eliminating risk.

CVSS provenance

nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck7.8HIGH
vendor_msrc7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.