Description
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE is unique from CVE-2018-0797 and CVE-2018-0812.
In plain language
AI Act nowThis is a serious Office Equation Editor bug that can let attackers run code, and it has been used in real ransomware attacks—if you use affected Microsoft Office versions, you should act now to install the vendor fixes.
CVE-2018-0802 is a remote code execution vulnerability in the Microsoft Equation Editor used by Microsoft Office (including Office 2007/2010/2013/2016, Office Compatibility Pack, and Equation Editor); attackers can trigger memory corruption by sending a specially crafted Office file to a user, which is then handled by the Equation Editor.
What to do now
- Check whether your business devices use Microsoft Office Equation Editor (often via Microsoft Word/Office 2007/2010/2013/2016, Microsoft Office Compatibility Pack, or Equation Editor) and confirm the installed version/service pack.
- Identify whether you have one of the affected configurations listed for Microsoft Office/Equation Editor (for example: Office 2016 Click-to-Run C2R, or the listed Word service packs).
- Update Microsoft Office/Equation Editor immediately using Microsoft’s guidance for CVE-2018-0802.
- Verify after updating that the device has the vendor-provided security fix for CVE-2018-0802 (by checking the installed Office build/patch level against the vendor instructions).
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply updates per vendor instructions.
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- Exploits and vulnerabilities in Q2 2026en-us·Kaspersky Securelist· PoC Windows Defender zero-day
- Inside the Stealthy Agent Tesla Infection Chainen-us·Daily CyberSecurity (securityonline.info)· Exploited Agent Tesla phishing
- Cloud Atlas activity in the second half of 2025 and early 2026: new tools and a new payloaden-us·Kaspersky Securelist· Exploited VBCloud Cloud Atlas
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2018-0802 and every CVE in our database. Create a free account — no credit card required.
Create Free Account