CVE-2017-11882This vulnerability is part of CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation in the wild. It has been observed in ransomware campaigns.
Microsoft Office contains a memory corruption vulnerability that allows remote code execution in the context of the current user.
Microsoft
Office
See vendor advisoryThis vulnerability was identified in Office by Microsoft. Microsoft Office contains a memory corruption vulnerability that allows remote code execution in the context of the current user.
High - Known ransomware exploitation
Complete system compromise possible
https://nvd.nist.gov/vuln/detail/CVE-2017-11882
Apply updates per vendor instructions.
Due Date: 5/3/2022