EXPOSURES › CVE-2017-0261
CVE-2017-0261
HIGH ⌖ ON CISA KEV · EXPLOITEDMicrosoft Office contained a use-after-free vulnerability allowing remote code execution that was actively exploited in the wild.
A use-after-free flaw in Microsoft Office enabled remote code execution, and because it was listed in CISA's KEV catalog, it was actively exploited in the wild. DIB organizations must ensure all Office applications are patched to the latest version to prevent attackers from executing arbitrary code on their systems. This failure highlights the critical importance of maintaining up-to-date software to mitigate known, actively exploited vulnerabilities.
Shame score — The vulnerability was actively exploited in the wild and allowed remote code execution, representing a severe and avoidable risk that DIB organizations must mitigate through strict patch management.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Office contains a use-after-free vulnerability which can allow for remote code execution.
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |