KEV · Actively exploited
CVE-2017-11826
CVE-2017-11826 is actively exploited (CISA KEV catalog) : high severity (CVSS 7.8), 2 tracked apps concerned, none still exposed on their current version.
- Severity (CVSS)
- 7.8
- Exploitation
- Confirmed
- Tracked apps
- 2
- Still exposed
- 0
NVD scale
CISA KEV · EPSS predicts 81.3 %
Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word Viewer, Word 2007, 2010, 2013 and 2016, Word Automation Services, and Office Online Server allow remote code execution when the software fails to properly handle objects in memory.
Show raw CVSS vector
CISA Known Exploited Vulnerability
- Added to KEV
- 2022-03-03
- Remediation deadline
- 2022-03-24
- Required action
- Apply updates per vendor instructions.
- Ransomware
- Unknown (not documented by CISA)
Tracked apps referencing this CVE
For each app: the affected range, the fixing version, and where the tracked app stands today.
-
-
Affected - Fixed in - Latest tracked - undetermined
NVD references 7 distinct products for this CVE : only those tracked by Scout (mobile and desktop catalog apps) are listed above. Libraries, servers and out-of-scope products do not appear here. Full list on NVD ↗
Vulnerable CPE configurations (10)
| Vendor | Product | Platform | Versions | CPE 2.3 URI |
|---|---|---|---|---|
| microsoft |
word All platforms (wildcard)
|
All platforms (wildcard) | - | cpe:2.3:a:microsoft:word:2007:sp3:*:*:*:*:*:* |
| microsoft |
word All platforms (wildcard)
|
All platforms (wildcard) | - | cpe:2.3:a:microsoft:word:2007:sp3:*:*:*:*:*:* |
| microsoft |
word All platforms (wildcard)
|
All platforms (wildcard) | - | cpe:2.3:a:microsoft:word:2010:sp2:*:*:*:*:*:* |
| microsoft |
word All platforms (wildcard)
|
All platforms (wildcard) | - | cpe:2.3:a:microsoft:word:2010:sp2:*:*:*:*:*:* |
| microsoft |
word All platforms (wildcard)
|
All platforms (wildcard) | - | cpe:2.3:a:microsoft:word:2013:sp1:*:*:-:*:*:* |
| microsoft |
word All platforms (wildcard)
|
All platforms (wildcard) | - | cpe:2.3:a:microsoft:word:2013:sp1:*:*:-:*:*:* |
| microsoft |
word All platforms (wildcard)
|
All platforms (wildcard) | - | cpe:2.3:a:microsoft:word:2013:sp1:*:*:rt:*:*:* |
| microsoft |
word All platforms (wildcard)
|
All platforms (wildcard) | - | cpe:2.3:a:microsoft:word:2013:sp1:*:*:rt:*:*:* |
| microsoft |
word All platforms (wildcard)
|
All platforms (wildcard) | - | cpe:2.3:a:microsoft:word:2016:*:*:*:*:*:*:* |
| microsoft |
word All platforms (wildcard)
|
All platforms (wildcard) | - | cpe:2.3:a:microsoft:word:2016:*:*:*:*:*:*:* |