Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Microsoft Office 2016 allow an attacker to run arbitrary code in the context of the current user by failing to properly handle objects in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11884.
CVE-2017-11882
Score elevated to 9.0 because this CVE is listed on the CISA Known Exploited Vulnerabilities catalog (added 2021-11-03), indicating real-world exploitation has been confirmed by US federal agencies. NVD baseline CVSS 7.8 retained for reference. Confidence: HIGH.
- Actively exploited in the wild (CISA-KEV)
No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.
- CVSS v3
- 7.8
- EG Score
- 9.0(high)
- EG Risk
- 81(Attend)EG Risk 81/100SSVC: Attend
EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).
How it’s computedSeverity90% × 45%Exploitation100% × 40%Automatability0% × 15%Action: Remediate soon — notable exploitation risk. - EPSS PROB
- 100%
- EPSS %ILE
- 100%
- KEV
- ⚠ Exploited
Published
November 15, 2017
Last Modified
June 17, 2026
Advisory Details (10)
Auto-updated May 19, 2026Security Update Guide - Microsoft Security Response Center
Security Update Guide - Microsoft Security Response Center. Patch available via Microsoft Security Update
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11882GitHub - rip1s/CVE-2017-11882: CVE-2017-11882 Exploit accepts over 17k bytes long command/code in maximum. · GitHub
https://github.com/unamer/CVE-2017-11882GitHub - rxwx/CVE-2017-11882: Proof-of-Concept exploits for CVE-2017-11882 · GitHub
https://github.com/rxwx/CVE-2017-11882GitHub - embedi/CVE-2017-11882: Proof-of-Concept exploits for CVE-2017-11882 · GitHub
https://github.com/embedi/CVE-2017-11882GitHub - 0x09AL/CVE-2017-11882-metasploit: This is a Metasploit module which exploits CVE-2017-11882 using the POC released here : https://embedi.com/blog/skeleton-closet-ms-office-vulnerability-you-didnt-know-about. · GitHub
https://github.com/0x09AL/CVE-2017-11882-metasploit0patch Blog: Microsoft's Manual Binary Patch For CVE-2017-11882 Meets 0patch
https://0patch.blogspot.com/2017/11/official-patch-for-cve-2017-11882-meets.html0patch Blog: Did Microsoft Just Manually Patch Their Equation Editor Executable? Why Yes, Yes They Did. (CVE-2017-11882)
https://0patch.blogspot.com/2017/11/did-microsoft-just-manually-patch-their.htmlLogdown - Site Maintenance
http://reversingminds-blog.logdown.com/posts/3907313-fileless-attack-in-word-without-macros-cve-2017-11882Vendor Advisories for CVE-2017-11882(1)
These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.
Weakness Classification(1)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Data Freshness Timeline
(refreshed 93× in last 7d / 386× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
Showing the most recent 100 of 1,295 total refreshes for this CVE.
- 2026-09-08 10:57 UTCVendor advisory
- 2026-09-08 10:57 UTCGHSA enrichment
- 2026-09-08 07:16 UTCVendor advisory
- 2026-09-08 07:16 UTCGHSA enrichment
- 2026-09-08 03:35 UTCVendor advisory
- 2026-09-08 03:35 UTCGHSA enrichment
- 2026-09-07 23:54 UTCVendor advisory
- 2026-09-07 23:53 UTCGHSA enrichment
- 2026-09-07 20:10 UTCVendor advisory
- 2026-09-07 20:10 UTCGHSA enrichment
- 2026-09-07 16:29 UTCVendor advisory
- 2026-09-07 16:29 UTCGHSA enrichment
- 2026-09-07 12:48 UTCVendor advisory
- 2026-09-07 12:48 UTCGHSA enrichment
- 2026-09-07 09:04 UTCVendor advisory
- 2026-09-07 09:03 UTCGHSA enrichment
- 2026-09-07 05:21 UTCVendor advisory
- 2026-09-07 05:21 UTCGHSA enrichment
- 2026-09-07 01:37 UTCVendor advisory
- 2026-09-07 01:37 UTCGHSA enrichment
- 2026-09-06 21:57 UTCVendor advisory
- 2026-09-06 21:57 UTCGHSA enrichment
- 2026-09-06 18:16 UTCVendor advisory
- 2026-09-06 18:16 UTCGHSA enrichment
- 2026-09-06 14:34 UTCVendor advisory
Show 75 moreShow fewer
- 2026-09-06 14:34 UTCGHSA enrichment
- 2026-09-06 10:53 UTCVendor advisory
- 2026-09-06 10:53 UTCGHSA enrichment
- 2026-09-06 07:12 UTCGHSA enrichment
- 2026-09-06 03:31 UTCVendor advisory
- 2026-09-06 03:31 UTCGHSA enrichment
- 2026-09-05 23:48 UTCVendor advisory
- 2026-09-05 23:48 UTCGHSA enrichment
- 2026-09-05 20:07 UTCVendor advisory
- 2026-09-05 20:07 UTCGHSA enrichment
- 2026-09-05 16:26 UTCVendor advisory
- 2026-09-05 16:26 UTCGHSA enrichment
- 2026-09-05 12:44 UTCVendor advisory
- 2026-09-05 12:44 UTCGHSA enrichment
- 2026-09-05 09:01 UTCVendor advisory
- 2026-09-05 09:01 UTCGHSA enrichment
- 2026-09-05 05:18 UTCVendor advisory
- 2026-09-05 05:18 UTCGHSA enrichment
- 2026-09-05 01:37 UTCVendor advisory
- 2026-09-05 01:37 UTCGHSA enrichment
- 2026-09-04 21:56 UTCVendor advisory
- 2026-09-04 21:56 UTCGHSA enrichment
- 2026-09-04 18:15 UTCVendor advisory
- 2026-09-04 18:14 UTCGHSA enrichment
- 2026-09-04 17:38 UTCCISA KEV update
- 2026-09-04 14:30 UTCVendor advisory
- 2026-09-04 14:30 UTCGHSA enrichment
- 2026-09-04 10:49 UTCVendor advisory
- 2026-09-04 10:49 UTCGHSA enrichment
- 2026-09-04 07:06 UTCVendor advisory
- 2026-09-04 07:05 UTCGHSA enrichment
- 2026-09-04 03:23 UTCVendor advisory
- 2026-09-04 03:22 UTCGHSA enrichment
- 2026-09-03 23:37 UTCVendor advisory
- 2026-09-03 23:37 UTCGHSA enrichment
- 2026-09-03 19:52 UTCVendor advisory
- 2026-09-03 19:52 UTCGHSA enrichment
- 2026-09-03 16:11 UTCVendor advisory
- 2026-09-03 16:11 UTCGHSA enrichment
- 2026-09-03 12:29 UTCVendor advisory
- 2026-09-03 12:29 UTCGHSA enrichment
- 2026-09-03 08:44 UTCVendor advisory
- 2026-09-03 08:44 UTCGHSA enrichment
- 2026-09-03 05:02 UTCVendor advisory
- 2026-09-03 05:02 UTCGHSA enrichment
- 2026-09-03 01:20 UTCVendor advisory
- 2026-09-03 01:20 UTCGHSA enrichment
- 2026-09-02 21:37 UTCVendor advisory
- 2026-09-02 21:37 UTCGHSA enrichment
- 2026-09-02 17:54 UTCVendor advisory
- 2026-09-02 17:54 UTCGHSA enrichment
- 2026-09-02 17:33 UTCCISA KEV update
- 2026-09-02 14:11 UTCVendor advisory
- 2026-09-02 14:11 UTCGHSA enrichment
- 2026-09-02 10:30 UTCVendor advisory
- 2026-09-02 10:30 UTCGHSA enrichment
- 2026-09-02 06:48 UTCVendor advisory
- 2026-09-02 06:48 UTCGHSA enrichment
- 2026-09-02 03:06 UTCVendor advisory
- 2026-09-02 03:06 UTCGHSA enrichment
- 2026-09-01 23:26 UTCVendor advisory
- 2026-09-01 23:26 UTCGHSA enrichment
- 2026-09-01 19:45 UTCVendor advisory
- 2026-09-01 19:44 UTCGHSA enrichment
- 2026-09-01 16:03 UTCVendor advisory
- 2026-09-01 16:02 UTCGHSA enrichment
- 2026-09-01 12:17 UTCVendor advisory
- 2026-09-01 12:16 UTCGHSA enrichment
- 2026-09-01 08:35 UTCVendor advisory
- 2026-09-01 08:35 UTCGHSA enrichment
- 2026-09-01 04:50 UTCVendor advisory
- 2026-09-01 04:50 UTCGHSA enrichment
- 2026-09-01 01:08 UTCVendor advisory
- 2026-09-01 01:08 UTCGHSA enrichment
- 2026-08-31 21:25 UTCVendor advisory
Publicly available exploits
(10 references)Working exploit code is in the public domain (9 GitHub PoCs) (1 Exploit-DB entry). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
- GitHub PoCRetr0-code/SignHereFirst seen Jan 25, 2021
SignHere is implementation of CVE-2017-11882. SignHere is builder of malicious rtf document and VBScript payloads.
Open source ↗ - Open source ↗GitHub PoClikekabin/CVE-2018-0802_CVE-2017-11882First seen Jan 16, 2018
- GitHub PoCRidter/RTF_11882_0802First seen Jan 12, 2018
PoC for CVE-2018-0802 And CVE-2017-11882
Open source ↗ - GitHub PoCrxwx/CVE-2018-0802First seen Jan 11, 2018
PoC Exploit for CVE-2018-0802 (and optionally CVE-2017-11882)
Open source ↗ - GitHub PoCstarnightcyber/CVE-2017-11882First seen Nov 22, 2017
CVE-2017-11882 exploitation
Open source ↗ - GitHub PoCBlackMathIT/2017-11882_GeneratorFirst seen Nov 21, 2017
CVE-2017-11882 File Generator PoC
Open source ↗ - GitHub PoCrip1s/CVE-2017-11882First seen Nov 21, 2017
CVE-2017-11882 Exploit accepts over 17k bytes long command/code in maximum.
Open source ↗ - GitHub PoCRidter/CVE-2017-11882First seen Nov 21, 2017
CVE-2017-11882 from https://github.com/embedi/CVE-2017-11882
Open source ↗ - GitHub PoC0x09AL/CVE-2017-11882-metasploitFirst seen Nov 21, 2017
This is a Metasploit module which exploits CVE-2017-11882 using the POC released here : https://embedi.com/blog/skeleton-closet-ms-office-vulnerability-you-didnt-know-about.
Open source ↗ - Exploit-DBEDB-43163First seen Nov 20, 2017
Microsoft Office - OLE Remote Code Execution
Open source ↗
Related CVEs(same vendor + same CWE)
Same vendor
10 shownmsrc
Same CWE
10 shownCWE-119
- CVE-2003-0819EG 10.0EPSS p99HIGH
- CVE-2003-0903EG 10.0EPSS p98HIGH
- CVE-2003-1339EG 10.0EPSS p99HIGH
- CVE-2003-0095EG 10.0EPSS p96HIGH
- CVE-2002-2227EG 10.0HIGH
- CVE-2002-2248EG 10.0EPSS p93HIGH
- CVE-2002-2250EG 10.0EPSS p94HIGH
- CVE-2002-2251EG 10.0EPSS p93HIGH
- CVE-2002-2253EG 10.0EPSS p93HIGH
- CVE-2002-2257EG 10.0EPSS p92HIGH
Frequently asked(6)
What is CVE-2017-11882?
When was CVE-2017-11882 disclosed?
Is CVE-2017-11882 actively exploited?
What is the CVSS score of CVE-2017-11882?
Which products are affected by CVE-2017-11882?
How do I remediate CVE-2017-11882?
Dependency Blast Radius
Explore the affected products and dependency analysis for CVE-2017-11882
Is Your Infrastructure Affected by CVE-2017-11882?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.