CVE-2017-11882
Microsoft Office Memory Corruption Vulnerability
- Published
- Nov 15, 2017
- Updated
- Oct 21, 2025
- Assigning CNA
- microsoft
- Evidence observed
- Nov 20, 2017
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HHigh · next 30 days
- Percentile
- 100.0%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
CISA Known Exploited
This CVE appears in the CISA Known Exploited Vulnerabilities catalog.
Summary
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Microsoft Office 2016 allow an attacker to run arbitrary code in the context of the current user by failing to properly handle objects in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11884.
Sources
29- CVE-2017-11882-metasploitExploit
This is a Metasploit module which exploits CVE-2017-11882 using the POC released here : https://embedi.com/blog/skeleton-closet-ms-office-vulnerability-you-didnt-know-about.
Proof-of-concept exploit for CVE-2017-11882 with WebDav-based remote execution, generating malicious RTF documents to trigger command execution via OLE objects.
- CVE-2017-11882Exploit
Python-based exploit for CVE-2017-11882 (Microsoft Office Equation Editor vulnerability) with command execution and mshta payload delivery via crafted .doc/.rtf files.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.