Vulnerability Manager Plus
Free Trial
  • Overview
  • Features
  • Demo
  • Documents
  • Get Quote
  • Support
Home
 

Microsoft Office Memory Corruption Vulnerability for Microsoft Office 2007 suites (KB4011604)

Risk Information

Base Score
7.8
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
9.3
MODERATE
Vector
AV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS Score
Exploitation Probability
No records found

CVE Information

Source CVE
CVE-2017-11882

Associated CVE
CVE-2017-11882

Patch Details

Patch associated with this vulnerability is supported by ManageEngine.

Patch ID
23487

Patch Description
Security Update for Microsoft Office 2007 suites (KB4011604)

References

http://reversingminds-blog.logdown.com/posts/3907313-fileless-attack-in-word-without-macros-cve-2017-11882
http://www.securityfocus.com/bid/101757
http://www.securitytracker.com/id/1039783
https://0patch.blogspot.com/2017/11/did-microsoft-just-manually-patch-their.html
https://0patch.blogspot.com/2017/11/official-patch-for-cve-2017-11882-meets.html
https://embedi.com/blog/skeleton-closet-ms-office-vulnerability-you-didnt-know-about
https://github.com/0x09AL/CVE-2017-11882-metasploit
https://github.com/embedi/CVE-2017-11882
https://github.com/rxwx/CVE-2017-11882
https://github.com/unamer/CVE-2017-11882
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2017-11882
https://researchcenter.paloaltonetworks.com/2017/12/unit42-analysis-of-cve-2017-11882-exploit-in-the-wild/
https://www.exploit-db.com/exploits/43163/
https://www.kb.cert.org/vuls/id/421280

Details

CWE ID
No records found
CWE Type
No records found
Vulnerability ID
14428
Published
2017-11-15
Updated
2026-03-21

Vulnerability Intelligence

Evaluate vulnerabilities across managed endpoints with enriched threat intelligence and risk context such as:

Risk Score
Emerging Risk Catalog
CERT Advisories
Risk Indicators