Vulnerability Manager Plus
Free Trial
  • Overview
  • Features
  • Demo
  • Documents
  • Get Quote
  • Support
Home
 

Microsoft Office/WordPad Remote Code Execution Vulnerability w/Windows for Microsoft Office 2010 (KB3141538) 32-Bit Edition - Petya ransomware attack (CVE-2017-0199)

Risk Information

Base Score
7.8
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
9.0
MODERATE
Vector
I:C/AV:N/Au:N/AC:M/A:C/C:C
EPSS Score
Exploitation Probability
94.327%

CVE Information

Source CVE
CVE-2017-0199

Associated CVE
CVE-2017-0199
ADV170005

Patch Details

No records found

References

http://rewtin.blogspot.nl/2017/04/cve-2017-0199-practical-exploitation-poc.html
http://www.securityfocus.com/bid/97498
http://www.securitytracker.com/id/1038224
https://blog.nviso.be/2017/04/12/analysis-of-a-cve-2017-0199-malicious-rtf-document/
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2017-0199
https://www.exploit-db.com/exploits/41894/
https://www.exploit-db.com/exploits/41934/
https://www.exploit-db.com/exploits/42995/
https://www.fireeye.com/blog/threat-research/2017/04/cve-2017-0199_useda.html
https://www.mdsec.co.uk/2017/04/exploiting-cve-2017-0199-hta-handler-vulnerability/
https://msrc.microsoft.com/update-guide/vulnerability/ADV170005

Details

CWE ID
CWE-20
CWE Type
Execute Code
Vulnerability ID
15121
Published
2017-04-11
Updated
2026-02-27

Vulnerability Intelligence

Evaluate vulnerabilities across managed endpoints with enriched threat intelligence and risk context such as:

Risk Score
Emerging Risk Catalog
CERT Advisories
Risk Indicators