EXPOSURES › CVE-2017-0199
CVE-2017-0199
CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
⚡ RCE
⌖ EXPLOITED IN THE WILD
SHAME 95/100
ransomwarerceexploited-in-wild
A Microsoft Office vulnerability allowed remote code execution via crafted files, actively exploited and linked to ransomware attacks.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
PLAYERS IMPLICATED
DESCRIPTION
Microsoft Office and WordPad contain an unspecified vulnerability due to the way the applications parse specially crafted files. Successful exploitation allows for remote code execution.
SENTIMENT · TRUSTED SOURCES
synthesis
negative
-0.50
Acknowledged vulnerability, but no specific praise or condemnation.
Neutral reporting of facts.
"Microsoft Office and WordPad contain an unspecified vulnerability due to the way the applications parse specially crafted files."
AFFECTED FEDRAMP PRODUCTS · 4
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |