CVE-2017-11826
Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word Viewer, Word 2007, 2010, 2013 and 2016, Word Automation Services, and Office Online Server allow remote code execution when the software fails to properly handle objects in memory.
Published:Oct 13, 2017
Last Modified:Apr 22, 2026
EPS:Oct 13, 2017
EPSS Score:0.90815
CVSS Score:7.8
CISA Notification
Description
Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word Viewer, Word 2007, 2010, 2013 and 2016, Word Automation Services, and Office Online Server allow remote code execution when the software fails to properly handle objects in memory.
Required Action:
Apply updates per vendor instructions.
Notes:
No extra notes provided.
Due Date
Mar 24, 2022
1632 days ago
Alert Date
Mar 3, 2022
1653 days ago
Affected Products
Vendor
Product
Action
Vendor
Microsoft
Product
Office Compatibility Pack
Microsoft
Office Compatibility Pack
Vendor
Microsoft
Product
Office Online Server
Microsoft
Office Online Server
Vendor
Microsoft
Product
Office Web Apps Server
Microsoft
Office Web Apps Server
Vendor
Microsoft
Product
Office Word Viewer
Microsoft
Office Word Viewer
Vendor
Microsoft
Product
Sharepoint Enterprise Server
Microsoft
Sharepoint Enterprise Server
Vendor
Microsoft
Product
Sharepoint Server
Microsoft
Sharepoint Server
Vendor
Microsoft
Product
Word
Microsoft
Word
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
