CVE Tools

Description

Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE is unique from CVE-2018-0797 and CVE-2018-0812.

In plain language

AI Act now

This is a serious Office Equation Editor bug that can let attackers run code, and it has been used in real ransomware attacks—if you use affected Microsoft Office versions, you should act now to install the vendor fixes.

Executive summary

CVE-2018-0802 is a remote code execution vulnerability in the Microsoft Equation Editor used by Microsoft Office (including Office 2007/2010/2013/2016, Office Compatibility Pack, and Equation Editor); attackers can trigger memory corruption by sending a specially crafted Office file to a user, which is then handled by the Equation Editor.

If affected, business impact
Full system compromiseRansomware infection riskData theft from workstationBusiness disruption via outage

What to do now

  1. Check whether your business devices use Microsoft Office Equation Editor (often via Microsoft Word/Office 2007/2010/2013/2016, Microsoft Office Compatibility Pack, or Equation Editor) and confirm the installed version/service pack.
  2. Identify whether you have one of the affected configurations listed for Microsoft Office/Equation Editor (for example: Office 2016 Click-to-Run C2R, or the listed Word service packs).
  3. Update Microsoft Office/Equation Editor immediately using Microsoft’s guidance for CVE-2018-0802.
  4. Verify after updating that the device has the vendor-provided security fix for CVE-2018-0802 (by checking the installed Office build/patch level against the vendor instructions).
Patch / advisory Some work to apply

CVSS Vector Breakdown

AV:LAC:LPR:NUI:RS:UC:HI:HA:H
Exploitability
AV:LAttack Vector
Local
AC:LAttack Complexity
Low
PR:NPrivileges Required
None
UI:RUser Interaction
Required
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

and 6 more affected products View all →

Exploitability

CISA Known Exploited Vulnerability
Added to KEV:Nov 3, 2021
Remediation due:May 3, 2022
Ransomware:Known ransomware use

Required action: Apply updates per vendor instructions.

6 exploit sources identified

Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.

View exploit details
Official Patch Available

Attack Graph

Products CVE Techniques Tactics

Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/ + scroll to zoom, or go fullscreen.

MITRE ATT&CK

2 techniques
Initial Access
Privilege Escalation
View detailed technique mapping

References

and 12 more references View all →
3

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2018-0802 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows