CISA Known Exploited Vulnerability

CVE-2017-11882 Ransomware

Microsoft · Office

Microsoft Office Memory Corruption Vulnerability

Date added
BOD 22-01 due date
CWE CWE-119
Ransomware Known

CISA description

Microsoft Office contains a memory corruption vulnerability that allows remote code execution in the context of the current user.

Required action

Apply updates per vendor instructions.