Buffer overflow in Microsoft Office - CVE-2017-11882
Published: November 14, 2017 / Updated: August 2, 2022
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to boundary error when processing Microsoft Office files. A remote unauthenticated attacker can create a specially crafted document, trick the victim into opening it and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system, but requires that a user open a specially crafted file with an affected version of Microsoft Office or Microsoft WordPad software.
Affected software
How to mitigate CVE-2017-11882
Additionally Microsoft has released a defense-in-depth update ADV170020.
Links to Public Exploits and PoC-codes
- Exploit #8204 - rtfkit (generate RTF exploit payload. uses cve-2017-11882, cve-2017-8570, cve-2018-0802, and cve-2018-8174.) (August 2, 2022)
- Exploit #4844 - rtfkit (generate RTF exploit payload. uses cve-2017-11882, cve-2017-8570, cve-2018-0802, and cve-2018-8174.) (November 17, 2020)
- Exploit #2376 - CVE-2017-11882-for-Kali (# CVE-2017-11882-metasploit This is a Metasploit module which exploits CVE-2017-11882 using the POC below: https://embedi.com/blog/skeleton-closet-ms-office-vulnerability-you-didnt-know-about. ## Installation 1) Copy the cve_20 (April 7, 2020)
- Exploit #1912 - exploits (MS17-010|CVE-2017-11882) (March 18, 2020)
- Exploit #1914 - CVE-2018-0802 (PoC Exploit for CVE-2018-0802 (and optionally CVE-2017-11882)) (March 18, 2020)
- Exploit #168 - CVE-2017-11882-metasploit (This is a Metasploit module which exploits CVE-2017-11882 using the POC released here : https://embedi.com/blog/skeleton-closet-ms-office-vulnerability-you-didnt-know-about.) (March 18, 2020)
- Exploit #169 - CVE-2017-11882 (CVE-2017-11882 exploitation) (March 18, 2020)
- Exploit #170 - CVE-2017-11882 (Proof-of-Concept exploits for CVE-2017-11882) (March 18, 2020)
- Exploit #171 - CVE-2017-11882 (CVE-2017-11882 Exploit accepts over 17k bytes long command/code in maximum.) (March 18, 2020)
- Exploit #1372 - Microsoft Office - OLE Remote Code Execution (March 18, 2020)
- Exploit #1626 - Microsoft Office CVE-2017-11882 (March 18, 2020)