Improper input validation in Microsoft Office - CVE-2017-0199
Published: April 9, 2017 / Updated: October 9, 2021
Vulnerability details
The vulnerability exists due to improper input validation. A remote unauthenticated attacker can create a specially crafted Office document, trick the victim into opening it with Microsoft Office or WordPad and execute arbitrary code on the target system with privileges of the current user.
Successful exploitation of this vulnerability may result in compromise vulnerable system.
Note: the vulnerability is being actively exploited.
Affected software
How to mitigate CVE-2017-0199
Links to Public Exploits and PoC-codes
- Exploit #6378 - Microsoft Office - 'Composite Moniker Remote Code Execution (June 17, 2021)
- Exploit #2372 - CVE-2017-8759 (NCC Group's analysis and exploitation of CVE-2017-8759 along with further refinements) (April 7, 2020)
- Exploit #2357 - CVE-2017-8570 (Proof of Concept exploit for CVE-2017-8570) (April 7, 2020)
- Exploit #2127 - htattack (An exploit implementation for RCE in RTF & DOCs (CVE-2017-0199)) (March 18, 2020)
- Exploit #132 - CVE-2017-0199 (Exploit toolkit CVE-2017-0199 - v2.0 is a handy python script which provides a quick and effective way to exploit Microsoft RTF RCE. It could generate a malicious RTF file and deliver metasploit / meterpreter / any other payload to victim w (March 18, 2020)
- Exploit #133 - PoC-CVE-2017-0199 (Exploit toolkit for vulnerability RCE Microsoft RTF) (March 18, 2020)
- Exploit #134 - CVE-2017-0199 (Exploit toolkit CVE-2017-0199 - v2.0 is a handy python script which provides a quick and effective way to exploit Microsoft RTF RCE. It could generate a malicious RTF file and deliver metasploit / meterpreter payload to victim without any c (March 18, 2020)
- Exploit #135 - CVE-2017-0199 (Exploit toolkit CVE-2017-0199 - v4.0 is a handy python script which provides pentesters and security researchers a quick and effective way to test Microsoft Office RCE. It could generate a malicious RTF/PPSX file and deliver metasploit / me (March 18, 2020)
- Exploit #136 - labs (Vulnerability Labs for security analysis) (March 18, 2020)
- Exploit #1151 - Microsoft Excel - OLE Arbitrary Code Execution (March 18, 2020)
- Exploit #1152 - Microsoft Office Word - Malicious Hta Execution (Metasploit) (March 18, 2020)
- Exploit #1153 - Microsoft Word - .RTF Remote Code Execution (March 18, 2020)
- Exploit #1622 - Microsoft Office Word Malicious Hta Execution (March 18, 2020)