CVE-2017-11884

HIGH EXPLOITED

Microsoft Excel 2016 C2R - Code Injection

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2017-11884 has been observed exploited in the wild (reported by VulnCheck KEV).

Description

Microsoft Excel 2016 Click-to-Run (C2R) allows an attacker to run arbitrary code in the context of the current user by failing to properly handle objects in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11882.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1039783
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/101766

Scores

CVSS v3 7.8
EPSS 0.4992
EPSS Percentile 97.9%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2024-04-04
CWE
CWE-119
Status published
Products (2)
microsoft/excel 2016
Microsoft Corporation/Microsoft Office Microsoft Excel 2016 Click-to-Run (C2R)
Published Nov 15, 2017
Tracked Since Feb 18, 2026