CVE-2017-0199CISA KEV
Microsoft Office and WordPad Remote Code Execution Vulnerability
CISA lists this Microsoft vulnerability as known exploited. Its MSRC release detail is outside this installation's collected history.
CISA catalog record
Microsoft Office and WordPad contain an unspecified vulnerability due to the way the applications parse specially crafted files. Successful exploitation allows for remote code execution.
- Product
- Office and WordPad
- Added to KEV
- 3 Nov 2021
- Federal remediation due
- 3 May 2022
- Known ransomware use
- Yes