CVE-2017-0199
Description
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, Windows 8.1 allow remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office/WordPad Remote Code Execution Vulnerability w/Windows API."
In plain language
AI Act nowCVE-2017-0199 is a serious Microsoft Office/WordPad and Windows flaw where a specially crafted document can trigger remote code execution, and you should treat it as an active ransomware-style threat if your systems are reachable and not fully updated.
CISA KEV confirms CVE-2017-0199 is exploited in real-world ransomware campaigns; it is triggered through crafted Office/WordPad documents to achieve remote code execution (a weakness that lets an attacker run code on a vulnerable Windows/Office installation).
What to do now
- Check whether you run any affected software on any machine in your business (Microsoft Office/WordPad and listed Windows versions).
- Verify the patch status against Microsoft’s CVE guidance and install the vendor-recommended updates for CVE-2017-0199.
- Ensure Microsoft Office/WordPad is updated to the latest supported builds available for your environment.
- If immediate patching is not possible, block opening documents from untrusted sources and temporarily restrict document download/attachment handling while you remediate.
- After updating, confirm the systems are updated successfully and monitor for follow-on activity from suspicious document delivery or abnormal processes.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply updates per vendor instructions.
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2017-0199 and every CVE in our database. Create a free account — no credit card required.
Create Free Account