CVE Tools

Description

Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, Windows 8.1 allow remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office/WordPad Remote Code Execution Vulnerability w/Windows API."

In plain language

AI Act now

CVE-2017-0199 is a serious Microsoft Office/WordPad and Windows flaw where a specially crafted document can trigger remote code execution, and you should treat it as an active ransomware-style threat if your systems are reachable and not fully updated.

Executive summary

CISA KEV confirms CVE-2017-0199 is exploited in real-world ransomware campaigns; it is triggered through crafted Office/WordPad documents to achieve remote code execution (a weakness that lets an attacker run code on a vulnerable Windows/Office installation).

If affected, business impact
Ransomware compromise of the PCServer takeover via infected documentsMalware installation and persistenceOperational disruption and downtime

What to do now

  1. Check whether you run any affected software on any machine in your business (Microsoft Office/WordPad and listed Windows versions).
  2. Verify the patch status against Microsoft’s CVE guidance and install the vendor-recommended updates for CVE-2017-0199.
  3. Ensure Microsoft Office/WordPad is updated to the latest supported builds available for your environment.
  4. If immediate patching is not possible, block opening documents from untrusted sources and temporarily restrict document download/attachment handling while you remediate.
  5. After updating, confirm the systems are updated successfully and monitor for follow-on activity from suspicious document delivery or abnormal processes.
Patch / advisory Some work to apply

CVSS Vector Breakdown

AV:LAC:LPR:NUI:RS:UC:HI:HA:H
Exploitability
AV:LAttack Vector
Local
AC:LAttack Complexity
Low
PR:NPrivileges Required
None
UI:RUser Interaction
Required
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

and 6 more affected products View all →

Exploitability

CISA Known Exploited Vulnerability
Added to KEV:Nov 3, 2021
Remediation due:May 3, 2022
Ransomware:Known ransomware use

Required action: Apply updates per vendor instructions.

3 exploit sources identified

Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.

View exploit details
Official Patch Available

References

and 73 more references View all →
3

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2017-0199 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows