Skip to main content

CVE detail

CVE-2017-0199

Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, Windows 8.1 allow remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office/WordPad Remote Code Execution Vulnerability w/Windows API."

CVSS 7.8 · HighBuzz score 75.0KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 75.0

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 30.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
30.0
105 evidence mentions in the snapshot
Diversity score
20.0
9 sources across 2 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
105 source links · newest first
  • Threat actors have been spotted using a PowerShell-based shellcode loader to stealthily deploy Remcos RAT, a popular espionage-ready tool in line with a broader shift toward fileless techniques. As discovered by Qualys, the campaign executes a number of steps to phish an obfuscated .HTA (HTML Application) file that runs layered PowerShell scripts entirely in memory. […]

    newswww.csoonline.comMay 15, 2025, 3:00 PM
  • Threat actors are using a well-known modular malware loader, SmokeLoader, to exploit known Microsoft Office vulnerabilities and steal sensitive browser credentials. The loader which runs a framework to deploy multiple malware modules, was observed by Fortinet’s FortiGuard Labs in attacks targeting manufacturing, healthcare, and IT companies in Taiwan. “SmokeLoader, known for its ability to deliver […]

    newswww.csoonline.comDec 3, 2024, 12:09 PM
  • Fortinet researchers discovered a new phishing campaign spreading a variant of the commercial malware Remcos RAT. Fortinet’s FortiGuard Labs recently uncovered a phishing campaign spreading a new variant of the Remcos RAT. Remcos is a commercial remote administration tool (RAT) that is sold online to allow buyers remote control over computers. Threat actors use Remcos […]

    newssecurityaffairs.comNov 11, 2024, 2:46 PM
  • The APT group SideWinder launched a new espionage campaign targeting ports and maritime facilities in the Indian Ocean and Mediterranean Sea. SideWinder (also known as Razor Tiger, Rattlesnake, and T-APT-04) has been active since at least 2012, the group mainly targeted Police, Military, Maritime, and the Naval forces of Central Asian countries. In the 2022 […]

    newssecurityaffairs.comJul 30, 2024, 3:00 PM
  • The SideWinder APT has been targeting ports and maritime facilities in the Indian Ocean and Mediterranean Sea in recent attacks.

    newswww.securityweek.comJul 30, 2024, 1:55 PM
  • A hacking campaign targeted Ukraine exploiting a seven-year-old vulnerability in Microsoft Office to deliver Cobalt Strike. Security experts at Deep Instinct Threat Lab have uncovered a targeted campaign against Ukraine, exploiting a Microsoft Office vulnerability dating back almost seven years to deploy Cobalt Strike on compromised systems. The researchers found a malicious PPSX (PowerPoint Slideshow […]

    newssecurityaffairs.comApr 28, 2024, 7:45 AM
  • 12th February – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 12th February, please download our Threat_Intelligence Bulletin. TOP ATTACKS AND BREACHES One of the largest unions in California, Service Employees International Union (SEIU) Local 1000, has confirmed a ransomware attack that led to network disruption. The LockBit ransomware gang has assumed responsibility, claiming to […]

    vendorresearch.checkpoint.comFeb 12, 2024, 4:01 PM
  • Maldocs ­of Word and Excel: Vigor of the AgesCheck Point Research

    Research by: Raman Ladutska We chose a fantasy decoration style at certain points of the article to attract attention to the described problem. We hope that visualizing a fantasy adventure as a fight against the source of evil will transform the real world and make it a safer and better place. Chasing new exploits, vulnerabilities, […]

    vendorresearch.checkpoint.comFeb 8, 2024, 1:43 PM
  • Old vulnerabilities are still a big problemHelp Net Security

    A recently flagged phishing campaign aimed at delivering the Agent Tesla RAT to unsuspecting users takes advantage of old vulnerabilities in Microsoft Office that allow remote code execution. “Despite fixes for CVE-2017-11882/CVE-2018-0802 being released by Microsoft in November, 2017 and January, 2018, this vulnerability remains popular amongst threat actors, suggesting there are still unpatched devices in the wild, even after over five years,” says Fortinet researcher Xiaopeng Zhang. “We are observing and mitigating 3000 attacks … More →

    newswww.helpnetsecurity.comSep 6, 2023, 1:51 PM
  • Top 12 vulnerabilities routinely exploited in 2022Help Net Security

    Cybersecurity agencies from member countries of the Five Eyes intelligence alliance have released a list of the top 12 vulnerabilities routinely exploited in 2022, plus 30 additional ones also “popular” with attackers. The top 12 “In 2022, malicious cyber actors exploited older software vulnerabilities more frequently than recently disclosed vulnerabilities and targeted unpatched, internet-facing systems. Proof of concept (PoC) code was publicly available for many of the software vulnerabilities or vulnerability chains likely facilitating exploitation … More →

    newswww.helpnetsecurity.comAug 4, 2023, 1:17 PM
  • Google warns that the North Korea-linked APT37 group is exploiting Internet Explorer zero-day flaw to spread malware. North Korea-linked APT37 group (aka ScarCruft, Reaper, and Group123) actively exploited an Internet Explorer zero-day vulnerability, tracked as CVE-2022-41128, in attacks aimed at South Korean users. Google Threat Analysis Group researchers discovered the zero-day vulnerability in late October 2022, it […]

    newssecurityaffairs.comDec 8, 2022, 3:08 PM
  • ets. The hidden malware residing in the documents exploited a vulnerability in the browser's JScript engine, tracked as CVE-2022-41128. Microsoft patches actively exploited Internet Explorer flaw Microsoft patches Internet Explorer zero-day under active attack Microsoft will stop supporting Internet Explorer in 2021 TAG attributed the attacks to APT37,

    newswww.itpro.comDec 8, 2022, 10:59 AM
  • The North Korea-linked APT group BlueNoroff has been spotted targeting cryptocurrency startups with fake MetaMask browser extensions. The North Korea-linked APT group BlueNoroff has been spotted targeting cryptocurrency startups with fake MetaMask browser extensions. The nation-state actor is considered a group that operates under the control of the notorious North Korea-linked Lazarus APT group. The […]

    newssecurityaffairs.comJan 14, 2022, 3:46 PM
  • Donot Team targeted a Togolese human rights advocate with a mobile spyware that has been allegedly developed by an Indian firm. Researchers from Amnesty International have uncovered a cyberespionage campaign tracked as ‘Donot Team‘ (aka APT-C-35), which was orchestrated by threat actors in India and Pakistan. Experts believe the attackers used a spyware developed by […]

    newssecurityaffairs.comOct 11, 2021, 1:51 PM
  • 29% of malware captured was previously unknown – due to the widespread use of packers and obfuscation techniques by attackers seeking to evade detection, according to a HP report. 88% of malware was delivered by email into users’ inboxes, in many cases having bypassed gateway filters. It took 8.8 days, on average, for threats to become known by hash to antivirus engines – giving hackers over a week’s ‘head-start’ to further their campaigns. “This report … More →

    newswww.helpnetsecurity.comMar 18, 2021, 4:30 AM
  • The typical timing of patch releases, exploits and CVE publication underscores the need for timely patching and effective vulnerability management.

    vendorunit42.paloaltonetworks.comAug 26, 2020, 1:00 PM
  • Attackers always seek out new ways to evade detection. As most endpoint security products handle file-based attacks relatively well, scripts are an excellent way for attackers to avoid making changes to a disk, thus bypassing the threat detection capabilities of most products. In today’s threat landscape, scripts provide initial access, enable evasion, and facilitate lateral movements post-infection. Attackers will use scripts directly on the machine or embed them in Office documents and PDFs sent to … More →

    newswww.helpnetsecurity.comJul 31, 2020, 4:30 AM
  • Microsoft’s security updates for June 2020 patch 129 vulnerabilities, including 11 critical remote code execution flaws affecting Windows, the Edge and Internet Explorer browsers, and SharePoint.

    newswww.securityweek.comJun 10, 2020, 3:32 AM
  • A threat actor believed to be operating out of China has been targeting physically isolated military networks in Taiwan and the Philippines, Trend Micro reports.

    newswww.securityweek.comMay 15, 2020, 3:24 PM
  • A recently identified cyber-espionage framework is capable of collecting and exfiltrating sensitive information even from air-gapped networks, ESET reports.

    newswww.securityweek.comMay 15, 2020, 11:29 AM
  • Experts discovered a new strain of malware dubbed Ramsay that can infect air-gapped computers and steal sensitive data, including Word, PDF, and ZIP files. Researchers from security firm ESET discovered a new advanced malware framework named Ramsay that appears to have been designed to infect air-gapped computers and exfiltrate sensitive data. The malicious code collects […]

    newssecurityaffairs.comMay 14, 2020, 8:26 AM
  • Several Microsoft Office vulnerabilities that were patched years ago continue to be among the security flaws most exploited in attacks, the U.S. government warns.

    newswww.securityweek.comMay 13, 2020, 4:43 PM
  • The US Cybersecurity and Infrastructure Security Agency (CISA) is urging organizations to patch a slew of old and new software vulnerabilities that are routinely exploited by foreign cyber actors and cyber criminals. “Foreign cyber actors continue to exploit publicly known—and often dated—software vulnerabilities against broad target sets, including public and private sector organizations. Exploitation of these vulnerabilities often requires fewer resources as compared with zero-day exploits for which no patches are available,” the agency noted. … More →

    newswww.helpnetsecurity.comMay 13, 2020, 9:49 AM
  • We identified 300+ COVID-19 themed malware samples that communicated with 20 unique IP addresses and domain IOCs.

    vendorunit42.paloaltonetworks.comMay 11, 2020, 2:54 PM
  • Security experts from Yoroy-Cybaze ZLab have conducted a detailed analysis of an implant used by the Gamaredon APT group in a recent campaign. Introduction Gamaredon Group is a Cyber Espionage persistent operation attributed to Russians FSB (Federal Security Service) in a long-term military and geo-political confrontation against the Ukrainian government and more in general against […]

    newssecurityaffairs.comFeb 17, 2020, 12:34 PM
  • Malaysia’s MyCERT issued a security alert to warn of a hacking campaign targeting government officials that was carried out by the China-linked APT40 group. Malaysia’s Computer Emergency Response Team (MyCERT) warns of a cyber espionage campaign carried out by the China-linked APT40 group aimed at Malaysian government officials. The attackers aimed at stealing confidential documents […]

    newssecurityaffairs.comFeb 10, 2020, 8:28 AM
  • Which ten software vulnerabilities should you patch as soon as possible (if you haven’t already)? Table of top exploited CVEs between 2016 and 2019 (repeats are noted by color) Recorded Future researchers have analyzed code repositories, underground forum postings, dark web sites, closed source reports and data sets comprising of submissions to popular malware repositories to compile a list of the ten most exploited vulnerabilities by cybercriminals in 2019. The list The list is comprised … More →

    newswww.helpnetsecurity.comFeb 6, 2020, 6:30 AM
  • The activity associated with a cybercrime campaign targeting hospitality companies with remote access Trojans and other malware has intensified this year, Kaspersky reports.

    newswww.securityweek.comDec 2, 2019, 3:11 PM
  • RevengeHotels campaign – The hospitality industry continues to be a privileged target for cybercriminals that target hotels, restaurant chains, and tourism services. Security experts at Kaspersky have published a report on a targeted cybercrime malware campaign, tracked as RevengeHotels, that hit hotels, hostels, hospitality and tourism companies. According to the experts, the threat actor has […]

    newssecurityaffairs.comNov 28, 2019, 6:48 PM
  • Researchers from MalwareBytes and HYAS Threat Intelligence linked one of the hacking groups under the Magecart umbrella to the notorious Cobalt cybercrime Group. Hacker groups under the Magecart umbrella continue to target organizations worldwide to steal payment card data with so-called software skimmers. Security firms have monitored the activities of a dozen groups at least since 2010. According to […]

    newssecurityaffairs.comOct 8, 2019, 2:14 PM
  • Security researchers were able to link one of the hacking groups operating under the Magecart umbrella to the infamous threat actor known as the Cobalt Group.

    newswww.securityweek.comOct 7, 2019, 6:23 PM
  • Magecart Group 4: A link with Cobalt Group?Malwarebytes Labs

    Note: This blog post is a collaboration between the Malwarebytes and HYAS Threat Intelligence teams.Magecart is a term that has become…

    newswww.malwarebytes.comOct 2, 2019, 5:00 PM
  • The experts at Yoroi-Cybaze Zlab described three techniques commonly implemented by threat actors to avoid detection. Introduction During our analysis we constantly run into the tricks cyber-attackers use to bypass companies security defences, sometimes advanced, others not. Many times, despite their elegance (or lack of it), these techniques are effective and actually help the cyber […]

    newssecurityaffairs.comMay 23, 2019, 10:17 AM
  • Eight of the top ten most exploited vulnerabilities in 2018 affected Microsoft products. Only one — but the second most exploited — was an Adobe vulnerability. The last one, ranking at the ninth most exploited vulnerability of 2018, was an Android vulnerability.

    newswww.securityweek.comMar 19, 2019, 4:26 PM
  • A cyber-espionage group, tracked as APT40, apparently linked to the Chinese government is focused on targeting countries important to the country’s Belt and Road Initiative. The cyber-espionage group tracked as APT40 (aka TEMP.Periscope, TEMP.Jumper, and Leviathan), apparently linked to the Chinese government, is focused on targeting countries important to the country’s Belt and Road Initiative […]

    newssecurityaffairs.comMar 6, 2019, 7:59 AM
  • A malicious campaign attempting to infect business users in the United States with a backdoor has been ongoing for over half a year, Proofpoint reports.

    newswww.securityweek.comFeb 26, 2019, 11:17 AM
  • A malware campaign using new LuckyCat-Linked RAT dubbed ExileRAT has been targeting the mailing list of the organization officially representing the Tibetan government-in-exile. Security experts at Talos group have uncovered a malware campaign using the ExileRAT backdoor to target the mailing list of the organization officially representing the Tibetan government-in-exile. Threat actors are delivering the malware via […]

    newssecurityaffairs.comFeb 6, 2019, 10:24 AM
  • A malware attack using a newly discovered backdoor has been targeting the mailing list of the organization officially representing the Tibetan government-in-exile.

    newswww.securityweek.comFeb 6, 2019, 3:44 AM
  • Unit 42 reveals new techniques to uncover and attribute Cobalt Gang commodity builders and infrastructure. Read the full report.

    vendorunit42.paloaltonetworks.comOct 25, 2018, 3:00 AM
  • A group of hackers believed to be operating out of China was observed using popular Microsoft Office exploits for the delivery of malware.

    newswww.securityweek.comOct 10, 2018, 5:01 PM
  • Slithering between nation state and cybercrime: Unit 42 examines the Gorgon Group’s unsophisticated yet effective attacks. Read the full report.

    vendorunit42.paloaltonetworks.comAug 2, 2018, 2:00 AM
  • A recently observed malicious campaign is abusing two chained Office documents, each exploiting a different vulnerability, to deliver the FELIXROOT Backdoor, FireEye reports.

    newswww.securityweek.comJul 30, 2018, 11:34 AM
  • Security experts from FireEye have spotted a new spam campaign leveraging the FELIXROOT backdoor, a malware used for cyber espionage operation. The FELIXROOT backdoor was first spotted by FireEye in September 2017, when attackers used it in attacks targeting Ukrainians. The new spam campaign used weaponized documents claiming to provide information on a seminar on environmental protection efforts. […]

    newssecurityaffairs.comJul 30, 2018, 7:25 AM
  • Unit 42 Threat Brief: Office Documents can be dangerous, however, we'll continue to use them anyway.

    vendorunit42.paloaltonetworks.comJul 24, 2018, 12:00 PM
  • Security experts from ESET uncovered an ongoing cyber espionage campaign aimed at Ukrainian government institutions and involving three different RATs, including the custom-made VERMIN. Security researchers from ESET uncovered an ongoing cyber espionage campaign aimed at Ukrainian government institutions, attackers used at least three different remote access Trojans (RATs). The campaign was first spotted in January by […]

    newssecurityaffairs.comJul 18, 2018, 9:04 AM
  • An ongoing espionage campaign aimed at Ukraine is leveraging three different remote access Trojans (RATs), ESET security researchers warn.

    newswww.securityweek.comJul 17, 2018, 5:53 PM
  • Two cyberespionage campaigns targeting the Tibetan community based in India appear to be the work of Chinese threat actors, a new Recorded Future report reveals.

    newswww.securityweek.comJun 27, 2018, 5:08 PM
  • Recently, the Advanced Threat Response Team of 360 Core Security Division detected an APT attack exploiting a 0-day vulnerability tracked as CVE-2018-8174. Now the experts published a detailed analysis of the flaw. I Overview Recently, the Advanced Threat Response Team of 360 Core Security Division detected an APT attack exploiting a 0-day vulnerability and captured the world’s […]

    newssecurityaffairs.comMay 10, 2018, 5:31 AM
  • A recently discovered Microsoft Office document exploit builder kit dubbed ThreadKit has been used to spread a variety of malware, including RATs and banking Trojans. Security experts at Proofpoint recently discovered a Microsoft Office document exploit builder kit dubbed ThreadKit that has been used to spread a variety of malware, including banking Trojans and RATs (i.e. Trickbot, Chthonic, FormBook and […]

    newssecurityaffairs.comMar 28, 2018, 12:37 PM
  • A newly discovered Microsoft Office document exploit builder kit has been used for the distribution of a variety of malicious payloads, including banking Trojans and backdoors, Proofpoint reports.

    newswww.securityweek.comMar 27, 2018, 3:29 PM
  • Cybercriminals are shifting their focus from Adobe to Microsoft consumer products, and are now concentrating more on targeted attacks than on web-based exploit kits.

    newswww.securityweek.comMar 27, 2018, 3:13 PM
  • The cost of having an organization targeted by a distributed denial of service (DDoS) attack for an hour is as low as $10, cybersecurity firm Armor says.

    newswww.securityweek.comMar 22, 2018, 4:54 PM
  • A malicious RTF (Rich Text Format) document has been persistently displaying an alert to ask users to enable macros, Zscaler security researchers have discovered.

    newswww.securityweek.comFeb 21, 2018, 1:05 PM
  • If the infamous bank robber, Willie Sutton , were alive today and honed his cyber skills, he might turn his attention to corporate espionage. Why? Because, as he once said about banks, “that’s where the money is.”

    newswww.securityweek.comFeb 1, 2018, 12:42 PM
  • Unit 42 observes a wave of attacks leveraging popular third party services to deliver malicious decoy documents.

    vendorunit42.paloaltonetworks.comJan 26, 2018, 3:00 AM
  • North Korean hackers belonging to the North Korea Group 123 have conducted at least six different massive malware campaigns during 2017. North Korean hackers have conducted at least six different massive malware campaigns during 2017, most of them against targets in South Korea. Security researchers from Cisco’s Talos group who have monitored the situation for 12 […]

    newssecurityaffairs.comJan 18, 2018, 4:41 PM
  • Cybercriminals and nation state groups were quick to adopt the most effective exploits last year, a new AlienVault report reveals.

    newswww.securityweek.comJan 17, 2018, 3:34 PM
  • McAfee released its McAfee Labs Threat Report: December 2017, examining the growth and trends of new malware, ransomware, and other threats in Q3 2017. McAfee Labs saw malware reach an all-time high of 57.6 million new samples – four new samples per second – featuring developments such as new fileless malware using malicious macros, a new version of Locky ransomware dubbed Lukitus, and new variations of the banking Trojans Trickbot and Emotet. Threats attempting to … More →

    newswww.helpnetsecurity.comDec 19, 2017, 12:00 PM
  • Malware campaigns attributed to the Patchwork cyberespionage group have been using a new delivery mechanism and exploiting recently patched vulnerabilities, Trend Micro warns.

    newswww.securityweek.comDec 12, 2017, 4:50 PM
  • A cyber espionage group linked to Iran has been using a recently patched Microsoft Office vulnerability to deliver malware to targeted organizations, FireEye reported on Thursday.

    newswww.securityweek.comDec 7, 2017, 6:41 PM
  • The notorious Cobalt hacking group has started to exploit a 17-year-old vulnerability in Microsoft Office that was addressed earlier this month, security researchers claim.

    newswww.securityweek.comNov 27, 2017, 6:40 PM
  • The NSA and CIA exploit leaks have thrown the spotlight on US government stockpiles of 0-day exploits — and possibly led to this week’s government declassification of the Vulnerabilities Equities Policy (VEP) process used to decide whether to disclose or retain the exploits it discovers.

    newswww.securityweek.comNov 16, 2017, 8:24 PM
  • Unit 42 tracks Subaat: a small phishing campaign targeting government organizations.

    vendorunit42.paloaltonetworks.comOct 27, 2017, 2:00 AM
  • Security researchers at Proofpoint spotted a cyber espionage campaign conducted by a group previously linked to China. The hackers have been using a recently patched .NET vulnerability, tracked as CVE-2017-8759, in attacks aimed at organizations in the United States. “Proofpoint researchers are tracking an espionage actor targeting organizations and high-value targets in defense and government. […]

    newssecurityaffairs.comOct 19, 2017, 7:53 AM
  • A cyber espionage group previously linked to China has been using a recently patched .NET vulnerability in attacks aimed at organizations in the United States, including a shipbuilding company and a university research center with ties to the military.

    newswww.securityweek.comOct 18, 2017, 2:16 PM
  • In this post, we take a look at a Microsoft Word document which itself is somewhat clean, but is used to…

    newswww.malwarebytes.comOct 12, 2017, 5:00 PM
  • OilRig group steps up attacks with new delivery documents and new injector trojan.

    vendorunit42.paloaltonetworks.comOct 9, 2017, 7:00 AM
  • Malicious actors have injected themselves into ongoing email exchanges in highly targeted spear-phishing attacks aimed at entities across the world, Palo Alto Networks said on Thursday.

    newswww.securityweek.comOct 6, 2017, 12:29 PM
  • Unit 42 uncovers FreeMilk: a highly targeted spear phishing campaign using hijacked conversations to deliver malware.

    vendorunit42.paloaltonetworks.comOct 5, 2017, 12:00 PM
  • The malware delivery trick involving updating links in Word documents is apparently gaining some traction: the latest campaign to use it likely takes the form of fake emails from the Internal Revenue Service (IRS). The fake email includes an attachment, supposedly a CP2000 notice, which is sent by the IRS when the income and/or payment information they have on file doesn’t match the information the person reported on his or her tax return. This mismatch … More →

    newswww.helpnetsecurity.comSep 22, 2017, 4:43 PM
  • Fake IRS notice delivers customized spying toolMalwarebytes Labs

    While macro-based documents and scripts make up for the majority of malspam attacks these days, we also see some campaigns that…

    newswww.malwarebytes.comSep 20, 2017, 5:00 PM
  • One of the vulnerabilities patched by Microsoft with this month’s security updates is a zero-day flaw exploited by threat actors to deliver FinFisher malware to Russian-speaking individuals.

    newswww.securityweek.comSep 12, 2017, 6:34 PM
  • Threat actors are leveraging malicious PowerPoint files and a recently patched Microsoft Office vulnerability to target UN agencies, foreign ministries, international organizations, and entities interacting with international governments, Fortinet warns.

    newswww.securityweek.comSep 6, 2017, 5:03 PM
  • Cloud-based online storage service Autodesk A360 Drive has been recently abused as a malware delivery platform, according to Trend Micro.

    newswww.securityweek.comSep 6, 2017, 3:03 PM
  • A new round of the weekly SecurityAffairs newsletter arrived! The best news of the week with Security Affairs. · Anti-Israel and pro-Palestinian IsraBye wiper spreads as a ransomware · Kenya opposition claims election results manipulated in cyber attack · MUGHTHESEC, a signed Mac adware that hijacks the victims browser for profit · Security Affairs newsletter […]

    newssecurityaffairs.comAug 20, 2017, 4:00 PM
  • The public availability of new exploit packages has fueled millions of new attacks on popular applications during the second quarter of 2017, a recent report from Kaspersky Lab reveals.

    newswww.securityweek.comAug 17, 2017, 5:25 PM
  • According to Trend Micro, cyber criminals abuse the CVE-2017-0199 vulnerability to deliver malware via PowerPoint Slide Show. In April Microsoft fixed the CVE-2017-0199 vulnerability in Office after threat actors had been exploiting it in the wild. Hackers leveraged weaponized Rich Text File (RTF) documents exploiting a flaw in Office’s Object Linking and Embedding (OLE) interface to deliver malware such […]

    newssecurityaffairs.comAug 15, 2017, 3:37 PM
  • Researchers at Trend Micro and Cisco’s Talos have identified a new wave of phishing attacks leveraging CVE-2017-0199, a previously patched remote code execution vulnerability in the OLE (Windows Object Linking and Embedding) interface of Microsoft Office. These latest attacks have paired the vulnerability with others in an attempt to bypass warning messages, but the results […]

    newswww.csoonline.comAug 15, 2017, 3:00 PM
  • Researchers at Cisco Talos have come across an attack that combines two Microsoft Office exploits, one old and one new, likely in an effort to avoid detection.

    newswww.securityweek.comAug 15, 2017, 8:27 AM
  • PowerPoint Slide Show Files Exploited for RAT Distribution

    newswww.securityweek.comAug 14, 2017, 9:48 PM
  • Trend Micro spotted a new espionage campaign that has been active for at least 2 months and that is targeting Russian-speaking firms with a new backdoor Security experts at Trend Micro have spotted a new cyber espionage campaign that has been active for at least two months and that is targeting Russian-speaking enterprises delivering a new Windows-based backdoor, […]

    newssecurityaffairs.comAug 11, 2017, 8:43 AM
  • While continuing to deploy their usual set of hacking tools onto compromised systems, advanced persistent threat (APT) actors were observed using leveraging zero-day vulnerabilities and quickly adopting new exploits during the second quarter of 2017, Kaspersky Lab reports.

    newswww.securityweek.comAug 10, 2017, 5:51 PM
  • A malicious email campaign that has been active for at least two months is targeting Russian-speaking enterprises and delivering a new Windows-based backdoor, Trend Micro warns.

    newswww.securityweek.comAug 8, 2017, 4:21 PM
  • After expanding operations to Americas earlier this year, the financially-motivated “ Cobalt” cybercriminal group has changed techniques and is now using supply chain attacks to target an organization’s partners, Positive Technologies reveals.

    newswww.securityweek.comAug 2, 2017, 5:01 PM
  • The winners of the 2017 Pwnie Awards were announced last night at the Black Hat USA security conference. The annual ceremony awards the very best and worst coming out of the security community. People previously nominated their opinions of the biggest achievements and failures over the last year; the award winners are chosen from the […]

    newswww.csoonline.comJul 27, 2017, 4:23 PM
  • An Iran-linked threat group named by researchers CopyKittens has been conducting foreign espionage on strategic targets in various countries. Trend Micro and ClearSky have published a report detailing the actor’s activities, including targets, tools and attack methods. The first report on CopyKittens was published in November 2015, but the group is believed to have been active since at least 2013. The hackers initially appeared to mainly target Israeli individuals , including diplomats and researchers, but further analysis showed that its operations have also covered entities in Saudi Arabia, Turkey, the United States, Jordan and Germany. The list of targets includes government organizations, academic institutions, IT firms, defense companies and contractors, municipal authorities, and employees of the United Nations. According to the latest report on CopyKittens activity, dubbed Operation Wilted Tulip , the hackers have used a wide range of tools and tactics. In some cases, they reli…

    newswww.securityweek.comJul 25, 2017, 12:51 PM
  • Companies in the video game industry and possibly other sectors have been targeted in attacks involving improved variants of the notorious PlugX remote access trojan (RAT).

    newswww.securityweek.comJun 28, 2017, 12:00 PM
  • Updated 3:19PM Pacific Time: A method to ‘vaccinate’ yourself against this ransomware variant has been found. I have posted details towards the end of the post along with a batch file you can run. It is as simple as creating the file C:\Windows\perfc and marking it read-only. Update 2 at 7pm PST on Tuesday: It appears that … Read More

    vendorwww.wordfence.comJun 27, 2017, 8:34 PM
  • Paranoid PlugXUnit42

    Unit 42 examines the continued effectiveness of Paranoid PlugX malware.

    vendorunit42.paloaltonetworks.comJun 27, 2017, 12:00 PM
  • 2017-6-26 Global Cyber Attack ReportsCheck Point Research

    TOP ATTACKS AND BREACHES Honda, the Japanese motor conglomerate, has halted its car production in one of its domestic car plants, after finding WannaCry ransomware in its network. The affected plant produces approximately 1,000 vehicles a day. It is unknown how and when Honda’s network got infected. In a related topic, WannaCry has hit 55 […]

    vendorresearch.checkpoint.comJun 26, 2017, 9:36 PM
  • A new round of the weekly SecurityAffairs newsletter arrived! The best news of the week with Security Affairs. First of all, let me inform you that at the #infosec16 SecurityAffairs was awarded as The Best European Personal Security Blog http://securityaffairs.co/wordpress/48202/breaking-news/securityaffairs-best-european-personal-security-blog.html · Hacker holds Netflix to ransom over new episodes of Orange Is The New Black · Lenovo […]

    newssecurityaffairs.comMay 7, 2017, 3:35 PM
  • Malware researchers at security firm ProofPoint reported the Chinese TA459 APT has exploited the CVE-2017-0199 vulnerability to target Financial firms. The notorious cyber espionage group tracked as TA459 APT has targeted analysts working at major financial firms using the recently patched CVE-2017-0199 Microsoft Office vulnerability. Experts at Proofpoint published a detailed analysis of the espionage campaign conducted […]

    newssecurityaffairs.comMay 3, 2017, 1:30 PM
  • A cyber espionage group has targeted analysts working at major financial firms using a recently patched Microsoft Office vulnerability, Proofpoint reported last week.

    newswww.securityweek.comMay 2, 2017, 9:33 AM
  • A recently patched vulnerability in Microsoft Office has been abused by Iranian threat actors in attacks against Israeli organizations, researchers from security firm Morphisec reveal.

    newswww.securityweek.comMay 1, 2017, 1:04 PM
  • According to the experts at the security firm Morphisec that massive attack against Israeli targets was powered by the OilRig APT group. Yesterday the Israeli Cyber Defense Authority announced it has thwarted a major cyberattack against 120 targets just days after harsh criticism of new cyber defense bill. In a first time, the authorities blamed a foreign […]

    newssecurityaffairs.comApr 28, 2017, 7:08 AM
  • A new round of the weekly SecurityAffairs newsletter arrived! The best news of the week with Security Affairs. First of all, let me inform you that at the #infosec16 SecurityAffairs was awarded as The Best European Personal Security Blog http://securityaffairs.co/wordpress/48202/breaking-news/securityaffairs-best-european-personal-security-blog.html · Facebook dismantled a huge spam campaign leveraging bogus accounts · Security Affairs newsletter Round 107 – […]

    newssecurityaffairs.comApr 23, 2017, 11:20 AM
  • The Security expert David Routin (@Rewt_1) has detailed a step by step procedure to exploit the recently patched cve-2017-0199 vulnerability exploited in Windows attacks in the wild. Introduction Since several days the security community has been informed thanks to FireEye publication of different malware campaigns (Dridex…) leveraging the CVE-2017-0199. Several other publications were related to this vulnerability but […]

    newssecurityaffairs.comApr 17, 2017, 4:17 PM
  • A new round of the weekly SecurityAffairs newsletter arrived! The best news of the week with Security Affairs. First of all, let me inform you that at the #infosec16 SecurityAffairs was awarded as The Best European Personal Security Blog http://securityaffairs.co/wordpress/48202/breaking-news/securityaffairs-best-european-personal-security-blog.html · Millions of mobile phones and laptops potentially exposed to attack leveraging baseband zero-days · ATMitch – […]

    newssecurityaffairs.comApr 16, 2017, 10:55 AM
  • Security researchers at FireEye discovered that the Microsoft Word CVE-2017-0199 exploit was linked to cyberspying in Ukraine conflict. The zero-day vulnerability in Microsoft Office that was recently fixed by Microsoft was used to deliver a surveillance malware to Russian-speaking targets. Security experts from firm FireEye spotted the targeted attacks leveraging specifically crafted Microsoft Word documents that […]

    newssecurityaffairs.comApr 13, 2017, 5:32 PM
  • A Microsoft Office 0-day vulnerability that was disclosed just days ago is already being exploited by attackers associated with malware families such as Latentbot and WingBird.

    newswww.securityweek.comApr 13, 2017, 12:21 PM
  • Microsoft released its monthly security-patch bundle Tuesday, fixing 45 unique vulnerabilities, three of which are publicly known and targeted by hackers. The top priority this month should be given to the Microsoft Office security update because one of the fixed flaws has been actively exploited by attackers since January to infect computers with malware. Over […]

    newswww.csoonline.comApr 12, 2017, 5:16 PM
  • Today Microsoft Patch Tuesday fixed the zero-day Word vulnerability that has been actively exploited in attacks in the wild. Microsoft today patched the zero-day Word vulnerability that has been exploited in attacks in the wild. Just yesterday I wrote about a phishing campaign leveraging the flaw to deliver the Dridex banking Trojan. Microsoft published security […]

    newssecurityaffairs.comApr 12, 2017, 8:29 AM
  • Adobe released security updates for several of its products on Tuesday to address a total of 59 vulnerabilities, including flaws disclosed last month at the Pwn2Own 2017 hacking competition.

    newswww.securityweek.comApr 12, 2017, 8:26 AM
  • Microsoft’s security updates for April 2017 address more than 40 critical, important and moderate severity vulnerabilities, including three zero-day flaws that have been exploited in attacks.

    newswww.securityweek.comApr 12, 2017, 7:09 AM
  • Forget about security bulletins; Microsoft is so done with them. Now, it’s all about the Security Update Guide—something Microsoft claimed customers wanted back in November 2016. Bulletins were supposed to bite the dust starting in January 2017, but it appears as if their disappearance started in April 2017. This new era for patching Microsoft is […]

    newswww.csoonline.comApr 11, 2017, 7:33 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence