Skip to main content

CVE detail

CVE-2017-11882

Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Microsoft Office 2016 allow an attacker to run arbitrary code in the context of the current user by failing to properly handle objects in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11884.

CVSS 7.8 · HighBuzz score 72.5KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 72.5

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 30.0 · diversity 17.5 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
30.0
119 evidence mentions in the snapshot
Diversity score
17.5
7 sources across 2 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
119 source links · newest first
  • FBI warns that North Korea–linked APT group Kimsuky is targeting governments, think tanks, and academic institutions with quishing attacks. North Korea–linked APT group Kimsuky is targeting government agencies, academic institutions, and think tanks using spear-phishing emails that contain malicious QR codes (quishing), the FBI warns. “As of 2025, Kimsuky actors have targeted think tanks, academic […]

    newssecurityaffairs.comJan 10, 2026, 3:34 PM
  • The infamous BlueKeep flaw from 2019, tracked as CVE-2019-0708, has come back to haunt security professionals as reports of fresh, in-the-wild abuse surface. The dangerous, “wormable” RCE flaw affecting Microsoft’s remote desktop protocol (RDP) was exploited in a new campaign by North Korea-backed Kimsuky APT, targeting vulnerable South Korean and Japanese systems. South Korean cybersecurity […]

    newswww.csoonline.comApr 22, 2025, 11:56 AM
  • Researchers spotted a new North Korea-linked group Kimsuky ‘s campaign, exploiting a patched Microsoft Remote Desktop Services flaw to gain initial access. While investigating a security breach, the AhnLab SEcurity intelligence Center (ASEC) researchers discovered a North Korea-linked group Kimsuky ‘s campaign, tracked as Larva-24005. Attackers exploited an RDP vulnerability to gain initial access to […]

    newssecurityaffairs.comApr 21, 2025, 6:25 PM
  • The APT group SideWinder targets maritime and logistics companies across South and Southeast Asia, the Middle East, and Africa. Kaspersky researchers warn that the APT group SideWinder (also known as Razor Tiger, Rattlesnake, and T-APT-04) is targeting maritime, logistics, nuclear, telecom, and IT sectors across South Asia, Southeast Asia, the Middle East, and Africa. SideWinder (also […]

    newssecurityaffairs.comMar 11, 2025, 11:22 AM
  • Threat actors are using a well-known modular malware loader, SmokeLoader, to exploit known Microsoft Office vulnerabilities and steal sensitive browser credentials. The loader which runs a framework to deploy multiple malware modules, was observed by Fortinet’s FortiGuard Labs in attacks targeting manufacturing, healthcare, and IT companies in Taiwan. “SmokeLoader, known for its ability to deliver […]

    newswww.csoonline.comDec 3, 2024, 12:09 PM
  • The APT group SideWinder launched a new espionage campaign targeting ports and maritime facilities in the Indian Ocean and Mediterranean Sea. SideWinder (also known as Razor Tiger, Rattlesnake, and T-APT-04) has been active since at least 2012, the group mainly targeted Police, Military, Maritime, and the Naval forces of Central Asian countries. In the 2022 […]

    newssecurityaffairs.comJul 30, 2024, 3:00 PM
  • The SideWinder APT has been targeting ports and maritime facilities in the Indian Ocean and Mediterranean Sea in recent attacks.

    newswww.securityweek.comJul 30, 2024, 1:55 PM
  • 12th February – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 12th February, please download our Threat_Intelligence Bulletin. TOP ATTACKS AND BREACHES One of the largest unions in California, Service Employees International Union (SEIU) Local 1000, has confirmed a ransomware attack that led to network disruption. The LockBit ransomware gang has assumed responsibility, claiming to […]

    vendorresearch.checkpoint.comFeb 12, 2024, 4:01 PM
  • Maldocs ­of Word and Excel: Vigor of the AgesCheck Point Research

    Research by: Raman Ladutska We chose a fantasy decoration style at certain points of the article to attract attention to the described problem. We hope that visualizing a fantasy adventure as a fight against the source of evil will transform the real world and make it a safer and better place. Chasing new exploits, vulnerabilities, […]

    vendorresearch.checkpoint.comFeb 8, 2024, 1:43 PM
  • A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs are free for you in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. LockBit ransomware gang claims to have breached accountancy firm Xeinadin Mobile virtual network operator Mint Mobile […]

    newssecurityaffairs.comDec 25, 2023, 12:37 AM
  • Threat actors are exploiting an old Microsoft Office vulnerability, tracked as CVE-2017-11882, to spread the Agent Tesla malware. Threat actors are exploiting an old Microsoft Office vulnerability, tracked as CVE-2017-11882 (CVSS score: 7.8), as part of phishing campaigns to spread the Agent Tesla malware. Agent Tesla is a spyware that is used to spy on the […]

    newssecurityaffairs.comDec 21, 2023, 2:22 PM
  • Old vulnerabilities are still a big problemHelp Net Security

    A recently flagged phishing campaign aimed at delivering the Agent Tesla RAT to unsuspecting users takes advantage of old vulnerabilities in Microsoft Office that allow remote code execution. “Despite fixes for CVE-2017-11882/CVE-2018-0802 being released by Microsoft in November, 2017 and January, 2018, this vulnerability remains popular amongst threat actors, suggesting there are still unpatched devices in the wild, even after over five years,” says Fortinet researcher Xiaopeng Zhang. “We are observing and mitigating 3000 attacks … More →

    newswww.helpnetsecurity.comSep 6, 2023, 1:51 PM
  • Top 12 vulnerabilities routinely exploited in 2022Help Net Security

    Cybersecurity agencies from member countries of the Five Eyes intelligence alliance have released a list of the top 12 vulnerabilities routinely exploited in 2022, plus 30 additional ones also “popular” with attackers. The top 12 “In 2022, malicious cyber actors exploited older software vulnerabilities more frequently than recently disclosed vulnerabilities and targeted unpatched, internet-facing systems. Proof of concept (PoC) code was publicly available for many of the software vulnerabilities or vulnerability chains likely facilitating exploitation … More →

    newswww.helpnetsecurity.comAug 4, 2023, 1:17 PM
  • Introduction Cloud Atlas (or Inception) is a cyber-espionage group. Since its discovery in 2014, they have launched multiple, highly targeted attacks on critical infrastructure across geographical zones and political conflicts. The group’s tactics, techniques and procedures (TTPs) have remained relatively static over the years. However, since the rapid escalation of the conflict between Russia […]

    vendorresearch.checkpoint.comDec 9, 2022, 2:12 PM
  • Trellix released The Threat Report: Fall 2022 from its Advanced Research Center, which analyzes cybersecurity trends from the third quarter (Q3) of 2022. The report includes evidence of malicious activity linked to ransomware and nation-state backed advanced persistent threat (APT) actors. It examines malicious cyberactivity including threats to email, the malicious use of legitimate third-party security tools, and more. Q3 cybersecurity trends US ransomware activity leads the pack: In the US alone, ransomware activity increased … More →

    newswww.helpnetsecurity.comNov 18, 2022, 4:00 AM
  • The latest Internet Security Report from the WatchGuard Threat Lab shows a reduction in overall malware detections from the peaks seen in the first half of 2021, along with an increase in threats for Chrome and Microsoft Office and the ongoing Emotet botnet resurgence. Office exploits on the rise “While overall malware attacks in Q2 fell off from the all-time highs seen in previous quarters, over 81% of detections came via TLS encrypted connections, continuing … More →

    newswww.helpnetsecurity.comSep 29, 2022, 5:15 AM
  • Since early this year, a known APT group of Chinese origin has been targeting military industrial complex enterprises and public institutions in Ukraine, Russia and Belarus, as well as in other parts of the world like Afghanistan. The group, tracked in the past as TA428, has an interesting approach where it deploys up to six […]

    newswww.csoonline.comAug 10, 2022, 11:58 AM
  • The August 2022 Patch Tuesday has arrived, with fixes for an unexpectedly high number of vulnerabilities in various Microsoft products, including two zero-days: one actively exploited (CVE-2022-34713) and one not yet (CVE-2022-30134). Vulnerabilities to prioritize CVE-2022-34713 is a vulnerability in Microsoft Windows Support Diagnostic Tool (MSDT) that allows for remote code execution. For an attacker to exploit it, they must trick targets into opening a specially crafted file (delivered via email or downloaded from a … More →

    newswww.helpnetsecurity.comAug 9, 2022, 8:30 PM
  • China-linked threat actors targeted dozens of industrial enterprises and public institutions in Afghanistan and Europe. In January 2022, researchers at Kaspersky ICS CERT uncovered a series of targeted attacks on military industrial enterprises and public institutions in Afghanistan and East Europe. The attackers breached dozens of enterprises and in some cases compromised their IT infrastructure, […]

    newssecurityaffairs.comAug 9, 2022, 2:52 PM
  • Emotet is the most common malwareHelp Net Security

    HP announced that the HP Wolf Security threat research team has identified a 27-fold increase in detections resulting from Emotet malicious spam campaigns in Q1 2022, compared to Q4 2021 – when Emotet first made its reappearance. The latest global HP Wolf Security Threat Insights Report – which provides analysis of real-world cybersecurity attacks – shows that Emotet has bolted up 36 places to become the most common malware family detected this quarter (representing 9% … More →

    newswww.helpnetsecurity.comMay 17, 2022, 4:00 AM
  • Network intrusion detections skyrocketingHelp Net Security

    A WatchGuard report shows a record number of evasive network malware detections with advanced threats increasing by 33%, indicating a higher level of zero day threats than ever before. Researchers detected malware threats in EMEA at a much higher rate than other regions of the world in Q4 2021, with malware detections per Firebox at 49%, compared to Americas at 23% and APAC at 29%. The trajectory of network intrusion detections also continued its upward … More →

    newswww.helpnetsecurity.comApr 8, 2022, 5:00 AM
  • Introduction Geopolitical tensions often make headlines and present a golden opportunity for threat actors to exploit the situation, especially those targeting high-profile victims. In the past month while the Russian invasion of Ukraine was unfolding, Check Point Research (CPR) has observed advanced persistent threat (APT) groups around the world launching new campaigns, or quickly adapting […]

    vendorresearch.checkpoint.comMar 31, 2022, 9:58 AM
  • Recently, the Malwarebytes Threat Intelligence Team found a Formbook campaigntargeting oil and gas companies. The campaign they discovered was delivered by…

    newswww.malwarebytes.comMar 4, 2022, 5:00 PM
  • An attack in early February targeted an energy organization in Ukraine with OutSteel and SaintBot. The attack is part of a larger campaign.

    vendorunit42.paloaltonetworks.comFeb 26, 2022, 1:30 AM
  • RDP brute-force attacks continue to be one of the most used attack vectors for breaching enterprise networks, ESET’s latest Threat Report has revealed. RDP brute-force attacks escalated throughout all of 2020 and 2021, and the last four months of 2021 brought a further acceleration, with an increase of 274% (from 55 billion in T2 2021 to 206 billion in T3 2021). But while the intensity of these attacks is growing, detections by the company’s solutions … More →

    newswww.helpnetsecurity.comFeb 9, 2022, 2:03 PM
  • Back in October 2021, Microsoft announced in an email to customers that it planned to disable Excel 4.0 macros by default…

    newswww.malwarebytes.comJan 24, 2022, 5:00 PM
  • 25th October – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 25th October, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Russia-based REvil ransomware gang, responsible for the Colonial Pipeline and Kaseya attacks among others, has been hacked and taken-down by law enforcement groups and intelligence agencies from different governments. Following the news […]

    vendorresearch.checkpoint.comOct 25, 2021, 12:13 PM
  • A comprehensive account of the evolution of SilverTerrier – threat actors based in Nigeria who are involved in business email compromise.

    vendorunit42.paloaltonetworks.comOct 7, 2021, 1:00 PM
  • Hacking tool downloads from underground forums are increasing, and the tools are becoming more sophisticated; low-level hackers are gaining access to hacked versions of sophisticated tools; access broking is growing; and existing tools are repurposed for more aggressive attacks.

    newswww.securityweek.comJul 29, 2021, 3:37 PM
  • The U.S. government and its allies are pleading with defenders to pay attention to gaping holes in perimeter-type devices, warning that advanced threat actors are feasting on known security defects in VPN appliances, network product gateways and enterprise cloud applications.

    newswww.securityweek.comJul 28, 2021, 3:28 PM
  • Check Point Research (CPR) said that the Chinese APT group SharpPanda spent three years developing a new backdoor to spy on Asian governments. Researchers from Check Point Research (CPR) discovered a new backdoor while investigating a cyber espionage campaign conducted by Chinese APT group SharpPanda and aimed at Southeast Asian government’s Ministry of Foreign […]

    newssecurityaffairs.comJun 6, 2021, 12:40 PM
  • Exploits for vulnerabilities in Microsoft’s Office suite were the most popular among cyber-attackers during the first quarter of this year, according to a new Kaspersky report.

    newswww.securityweek.comJun 1, 2021, 7:52 PM
  • A China-linked cyberespionage group targets a Russian defense contractor involved in designing nuclear submarines for the Russian Navy. Cybereason researchers reported that a China-linked APT group targets a Russian defense contractor involved in designing nuclear submarines for the Russian Navy. The state-sponsored hackers sent spear-phishing messages to a general director working at the Rubin Design […]

    newssecurityaffairs.comApr 30, 2021, 10:29 PM
  • Researchers from Cybereason Nocturnus Team have detected anomalous characteristics in a newly discovered RoyalRoad weaponizer that delivers a previously undocumented backdoor. The researchers have been tracking recent developments in the RoyalRoad when they uncovered an attack targeting a Russian-based defense contractor. Spear-phishing attack targets Russian defense contractor In this instance, the target of the spear-phishing […]

    newswww.csoonline.comApr 30, 2021, 12:57 PM
  • 29% of malware captured was previously unknown – due to the widespread use of packers and obfuscation techniques by attackers seeking to evade detection, according to a HP report. 88% of malware was delivered by email into users’ inboxes, in many cases having bypassed gateway filters. It took 8.8 days, on average, for threats to become known by hash to antivirus engines – giving hackers over a week’s ‘head-start’ to further their campaigns. “This report … More →

    newswww.helpnetsecurity.comMar 18, 2021, 4:30 AM
  • The business of cybercrime seems to be unhindered by the coronavirus this year. They continue to work hard through the pandemic, using it and other drivers to ply their trade. This year has been a banner year for them in many ways maximizing global events, with malware remaining a tried-and-true weapon of choice. The trends in malware that we’ve seen this year reflect both adversary intent and capability.

    newswww.securityweek.comDec 18, 2020, 3:00 PM
  • How to speed up malware analysisHelp Net Security

    Today malware evolves very fast. Loaders, stealers, and different types of ransomware change so quickly, so it’s become a real challenge to keep up with them. Along with that analysis of them becomes harder and more time-consuming. But cybersecurity specialists can’t waste their time, waiting can cause serious damage. So, how to avoid all of that and speed up malware analysis? Let’s find out. Malware analysis The goal of malware analysis is to research a … More →

    newswww.helpnetsecurity.comNov 17, 2020, 10:33 AM
  • The typical timing of patch releases, exploits and CVE publication underscores the need for timely patching and effective vulnerability management.

    vendorunit42.paloaltonetworks.comAug 26, 2020, 1:00 PM
  • Attackers always seek out new ways to evade detection. As most endpoint security products handle file-based attacks relatively well, scripts are an excellent way for attackers to avoid making changes to a disk, thus bypassing the threat detection capabilities of most products. In today’s threat landscape, scripts provide initial access, enable evasion, and facilitate lateral movements post-infection. Attackers will use scripts directly on the machine or embed them in Office documents and PDFs sent to … More →

    newswww.helpnetsecurity.comJul 31, 2020, 4:30 AM
  • In 2019, Microsoft Office became cybercriminals’ preferred platform when carrying out attacks, and the number of incidents keeps increasing, according to Kaspersky Lab researchers. Boris Larin, Vlad Stolyarov and Alexander Liskin showed at the company’s Security Analyst Summit that the threat landscape has changed in the past two years and urged users to keep their software […]

    newswww.csoonline.comJul 24, 2020, 10:00 AM
  • For years, a China-linked threat actor named Cycldek has been exfiltrating data from air-gapped systems using a previously unreported, custom USB malware family, Kaspersky reports.

    newswww.securityweek.comJun 4, 2020, 3:28 PM
  • A recently identified cyber-espionage framework is capable of collecting and exfiltrating sensitive information even from air-gapped networks, ESET reports.

    newswww.securityweek.comMay 15, 2020, 11:29 AM
  • Experts discovered a new strain of malware dubbed Ramsay that can infect air-gapped computers and steal sensitive data, including Word, PDF, and ZIP files. Researchers from security firm ESET discovered a new advanced malware framework named Ramsay that appears to have been designed to infect air-gapped computers and exfiltrate sensitive data. The malicious code collects […]

    newssecurityaffairs.comMay 14, 2020, 8:26 AM
  • Several Microsoft Office vulnerabilities that were patched years ago continue to be among the security flaws most exploited in attacks, the U.S. government warns.

    newswww.securityweek.comMay 13, 2020, 4:43 PM
  • The US Cybersecurity and Infrastructure Security Agency (CISA) is urging organizations to patch a slew of old and new software vulnerabilities that are routinely exploited by foreign cyber actors and cyber criminals. “Foreign cyber actors continue to exploit publicly known—and often dated—software vulnerabilities against broad target sets, including public and private sector organizations. Exploitation of these vulnerabilities often requires fewer resources as compared with zero-day exploits for which no patches are available,” the agency noted. … More →

    newswww.helpnetsecurity.comMay 13, 2020, 9:49 AM
  • New campaigns using an updated BackConfig malware by Hangover group were found targeting government and military organizations in South Asia.

    vendorunit42.paloaltonetworks.comMay 12, 2020, 4:30 AM
  • We identified 300+ COVID-19 themed malware samples that communicated with 20 unique IP addresses and domain IOCs.

    vendorunit42.paloaltonetworks.comMay 11, 2020, 2:54 PM
  • A series of COVID-19 themed malware campaigns from the SilverTerrier group was blocked by Unit 42. 170+ phishing emails produced, with some targeting government healthcare agencies.

    vendorunit42.paloaltonetworks.comMay 7, 2020, 10:00 AM
  • As the coronavirus crisis continues to capture everyone’s attention, cybercriminals stay busy running scams and delivering malware using the attention-getting virus as a lure. The threats from the scammers and crooks, which began as early as January and continue unabated, range from tricking people out of their financial data to delivering pernicious malware. Although some […]

    newswww.csoonline.comApr 9, 2020, 10:00 AM
  • Looking for hard numbers to back up your sense of what’s happening in the cybersecurity world? We dug into studies and surveys of the industry’s landscape to get a sense of the lay of the land—both in terms of what’s happening and how security leaders are reacting to it. If you want data on what […]

    newswww.csoonline.comMar 9, 2020, 10:00 AM
  • Which ten software vulnerabilities should you patch as soon as possible (if you haven’t already)? Table of top exploited CVEs between 2016 and 2019 (repeats are noted by color) Recorded Future researchers have analyzed code repositories, underground forum postings, dark web sites, closed source reports and data sets comprising of submissions to popular malware repositories to compile a list of the ten most exploited vulnerabilities by cybercriminals in 2019. The list The list is comprised … More →

    newswww.helpnetsecurity.comFeb 6, 2020, 6:30 AM
  • Phoenix Keylogger Attempts to Disable More Than 80 security Products, Exfiltrates Data Direct from Memory The Phoenix Keylogger, operating at the cusp of keylogger and infostealer, was launched in July 2019. It is sold as malware-as-a-service (MaaS), and appears to be gaining traction in the criminal underworld.

    newswww.securityweek.comNov 20, 2019, 5:30 PM
  • Security expert Marco Ramilli published a quick analysis of an interesting attack carried out by SWEED threat actor targeting precision engineering firms in Italy. Introduction Today I’d like to share a quick analysis of an interesting attack targeting precision engineering companies based in Italy. Precision engineering is a very important business market in Europe, it […]

    newssecurityaffairs.comOct 28, 2019, 9:50 AM
  • Cloud Atlas threat actors used a new piece of polymorphic malware in recent attacks against government organizations. The Cloud Atlas cyberespionage group, aka Inception, continues to carry out attacks against government organizations and was observed using a new piece of polymorphic malware dubbed VBShower. The Cloud Atlas was first observed by researchers at Kaspersky Lab […]

    newssecurityaffairs.comAug 13, 2019, 6:28 AM
  • Today, Unit 42 released 11 new Adversary Playbooks as part of our mission to provide actionable threat intelligence. We use Playbooks to organize the tools, techniques, and procedures (TTPs) that an adversary uses into a structured format that can easily be shared and built upon. All of the Playbooks we have released can be accessed

    vendorunit42.paloaltonetworks.comJul 30, 2019, 1:00 PM
  • A threat actor active since at least 2017 has been mainly targeting victims with information stealers and remote access Trojans (RATs), Cisco’s Talos security researchers explain.

    newswww.securityweek.comJul 17, 2019, 6:11 AM
  • During an investigation into a possibly shared RTF weaponizer by Indian and Chinese APT groups, researchers have discovered that multiple Chinese groups have updated the weaponizer to exploit the Microsoft Equation Editor (EE) vulnerability CVE-2018-0798. The same weaponizer had previously delivered exploits for EE vulnerabilities CVE-2017-11882 and CVE-2018-0802.

    newswww.securityweek.comJul 3, 2019, 6:56 PM
  • 17th June – Threat Intelligence BulletinCheck Point Research

    For the latest discoveries in cyber research for the week of 10th June 2019, please download our Threat Intelligence Bulletin TOP ATTACKS AND BREACHES Belgium-based airplane parts and aviation structuring business ASCO Industries has shuttered its plants in Belgium, Germany, Canada and the US after falling victim to a ransomware attack. Nearly 1,000 […]

    vendorresearch.checkpoint.comJun 17, 2019, 4:47 PM
  • 10th June – Threat Intelligence BulletinCheck Point Research

    For the latest discoveries in cyber research for the week of 10th June 2019, please download our Threat Intelligence Bulletin TOP ATTACKS AND BREACHES American Medical Collection Agency (AMCA) has suffered a major data breach exposing personal and payment information of some ten million patients. The information included names, date of birth, address, […]

    vendorresearch.checkpoint.comJun 16, 2019, 8:09 AM
  • A new round of the weekly SecurityAffairs newsletter arrived! The best news of the week with Security Affairs. Kindle Edition Paper Copy Once again thank you! Critical RCE affects older Diebold Nixdorf ATMs Facebook is going to stop Huawei pre-installing apps on mobile devices Millions of Exim mail servers vulnerable to cyber attacks CIA sextortion […]

    newssecurityaffairs.comJun 16, 2019, 5:38 AM
  • The cyber-espionage group known as MuddyWater has used an updated multi-stage PowerShell backdoor in recent campaigns, Trend Micro’s security researchers report.

    newswww.securityweek.comJun 10, 2019, 5:49 PM
  • Emails delivering RTF files equipped with an exploit that requires no user interaction (except for opening the booby-trapped file) are hitting European users’ inboxes, Microsoft researchers have warned. Exploit delivers backdoor The exploit takes advantage of a vulnerability in an older version of the Office Equation Editor, which was manually patched by Microsoft in November 2017. “The CVE-2017-11882 vulnerability was fixed in 2017, but to this day, we still observe the exploit in attacks. Notably, … More →

    newswww.helpnetsecurity.comJun 10, 2019, 8:59 AM
  • Microsoft is warning of an active spam campaign targeting European languages that leverages an exploit to infect simply by opening the attachment. Microsoft issued a warning on Friday about an ongoing spam campaign that is targeting European users. Spam messages are carrying weaponized RTF documents that could infect users with malware without any user interaction, […]

    newssecurityaffairs.comJun 10, 2019, 7:43 AM
  • Cisco Talos experts uncovered a new wave of attacks tracked as Frankenstein campaign, attackers used tools built by combining four open-source techniques. Security experts at Cisco Talos uncovered a series of highly targeted attacks, tracked as Frankenstein campaign, hackers used tools built by combining four different open-source techniques. Attackers behind the Frankenstein campaign carried out […]

    newssecurityaffairs.comJun 8, 2019, 8:40 AM
  • A recently detected cyberattack campaign utilized tools built by combining multiple open-source techniques, Cisco Talos security researchers say.

    newswww.securityweek.comJun 7, 2019, 1:13 PM
  • The Chinese government appears to have centralized control over several hacking groups previously believed to be separate threat actors, the BlackBerry Cylance Threat Intelligence security researchers say.

    newswww.securityweek.comMay 15, 2019, 8:27 PM
  • A new variant of the HawkEye data stealer emerges in the threat landscape as part of ongoing malware distribution campaigns. New malware campaigns leveraging a new variant of the HawkEye data stealer have been observed by experts at Talos. The malware has been under active development since at least 2013 and it is offered for […]

    newssecurityaffairs.comApr 17, 2019, 9:17 AM
  • A new variant of HawkEye, a piece of malware used for keylogging and data theft, is being leveraged in ongoing malware distribution campaigns, Cisco’s Talos security researchers warn.

    newswww.securityweek.comApr 16, 2019, 2:42 PM
  • Eight of the top ten most exploited vulnerabilities in 2018 affected Microsoft products. Only one — but the second most exploited — was an Adobe vulnerability. The last one, ranking at the ninth most exploited vulnerability of 2018, was an Android vulnerability.

    newswww.securityweek.comMar 19, 2019, 4:26 PM
  • A cyber-espionage group, tracked as APT40, apparently linked to the Chinese government is focused on targeting countries important to the country’s Belt and Road Initiative. The cyber-espionage group tracked as APT40 (aka TEMP.Periscope, TEMP.Jumper, and Leviathan), apparently linked to the Chinese government, is focused on targeting countries important to the country’s Belt and Road Initiative […]

    newssecurityaffairs.comMar 6, 2019, 7:59 AM
  • APT40 Hackers Appear to be Supporting China’s Belt and Road Initiative

    newswww.securityweek.comMar 5, 2019, 1:19 PM
  • Since at least 2015, a suspected South Asian threat grouping known as BITTER has been targeting Pakistan and Chinese organizations using variants of a previously unreported downloader. We have named this malware family ArtraDownloader. Starting in September 2018 and continuing through the beginning of 2019, BITTER launched a wave of attacks targeting Pakistan and Saudi Arabia. This is the first reported instance of BITTER targeting Saudi Arabia.

    vendorunit42.paloaltonetworks.comFeb 25, 2019, 2:00 PM
  • The return of the AdvisorsBot malwareSecurity Affairs

    Security experts at Cybaze– Yoroi ZLab have analyzed a new sample of the AdvisorsBot malware, a downloader that was first spotted in August 2018. As usual, the malware looks like a legitimate e-mail attachment, named as “invoice.doc”. Today, weaponized Microsoft office documents with macros, are one of the most common and more effective methods to […]

    newssecurityaffairs.comFeb 1, 2019, 4:46 PM
  • The ‘AVE_MARIA’ MalwareSecurity Affairs

    Ave Maria Malware – Phishing attempts spreading in the last days of the past year against an Italian organization operating in the Oil&Gas sector The Cybaze-Yoroi ZLab researchers analyzed phishing attempts spreading in the last days of the past year against an Italian organization operating in the Oil&Gas sector. The malicious emails try to impersonate […]

    newssecurityaffairs.comJan 11, 2019, 12:54 PM
  • For the past couple of years, Office documents have largely replaced exploit kits as the primary malware delivery vector, giving threat…

    newswww.malwarebytes.comDec 4, 2018, 5:00 PM
  • Recent attacks on an engineering company in the United Kingdom were attributed to a China-related cyber-espionage group despite the use of techniques usually associated with Russian threat actors.

    newswww.securityweek.comNov 14, 2018, 5:06 PM
  • A malicious group known as the “Inception” attackers has been using a year-old Office exploit and a new backdoor in recent attacks, Palo Alto Networks security researchers warn.

    newswww.securityweek.comNov 9, 2018, 3:43 PM
  • Inception targets Europe with year old office vulnerability. Read the full report.

    vendorunit42.paloaltonetworks.comNov 5, 2018, 4:00 PM
  • Yoroi security firm uncovered a targeted attack against one of the most important companies in the Italian Naval Industry leveraging MartyMcFly Malware. Today I’d like to share an interesting analysis of a Targeted Attack found and dissected by Yoroi (technical details are available here). The victim was one of the most important leaders in the field of security and defensive military […]

    newssecurityaffairs.comOct 17, 2018, 7:14 PM
  • A newly discovered infection campaign is leveraging malicious RTF files to deliver information-stealing Trojans to the unsuspecting victims, Cisco Talos security researchers warn.

    newswww.securityweek.comOct 16, 2018, 2:55 PM
  • What appears to be a new campaign delivering the Betabot malware has been detected by security researchers. It doesn’t look as if this campaign is directly related to the wide-ranging campaign disclosed by Kaspersky Lab in August. However, like the Kaspersky campaign, this one also uses phishing as the original point of infection.

    newswww.securityweek.comOct 3, 2018, 3:57 PM
  • The Russian Cobalt crime gang was particularly active in the last month, a new report confirms a massive use of the CobInt malware in recent attacks. Security researchers from Proofpoint reported the massive use of the CobInt malware by the Cobalt group in recent attacks. The Cobalt name is based on the association of the […]

    newssecurityaffairs.comSep 13, 2018, 7:56 AM
  • The Russia-based Cobalt hacking group has made heavy use of the CobInt malware in recently observed campaigns, Proofpoint’s security researchers warn.

    newswww.securityweek.comSep 12, 2018, 11:42 PM
  • A recently observed malicious campaign is abusing two chained Office documents, each exploiting a different vulnerability, to deliver the FELIXROOT Backdoor, FireEye reports.

    newswww.securityweek.comJul 30, 2018, 11:34 AM
  • Security experts from FireEye have spotted a new spam campaign leveraging the FELIXROOT backdoor, a malware used for cyber espionage operation. The FELIXROOT backdoor was first spotted by FireEye in September 2017, when attackers used it in attacks targeting Ukrainians. The new spam campaign used weaponized documents claiming to provide information on a seminar on environmental protection efforts. […]

    newssecurityaffairs.comJul 30, 2018, 7:25 AM
  • Researchers from Proofpoint have discovered a new variant of the infamous Kronos banking Trojan that was involved in several attacks in the recent months. The infamous Kronos banking Trojan is back, and according to the experts from Proofpoint it was involved in several attacks in the last months. The malware was first spotted in 2014 by researchers at […]

    newssecurityaffairs.comJul 26, 2018, 7:29 AM
  • Kronos Banking Trojan Has ReturnedSecurityWeek

    The Kronos banking Trojan is showing renewed strength and has been very active over the past several months, Proofpoint security researchers warn.

    newswww.securityweek.comJul 25, 2018, 2:46 PM
  • Unit 42 Threat Brief: Office Documents can be dangerous, however, we'll continue to use them anyway.

    vendorunit42.paloaltonetworks.comJul 24, 2018, 12:00 PM
  • Security researchers from Italian security firm TG Soft have uncovered an ongoing malware campaigns targeting Samsung service centers in Italy. “TG Soft’s Research Centre (C.R.A.M.) has analyzed the campaign of spear-phishing on 2 april 2018 targeting the service centers of Samsung Italy.” reads the analysis published by TG Soft. “The campaign analyzed is targeting only the service centers of Samsung […]

    newssecurityaffairs.comJul 18, 2018, 6:53 AM
  • A China-linked APT group, LuckyMouse, Emissary Panda, APT27 and Threat Group 3390, has targeted a national data center in Central Asia. The APT group has been active since at least 2010, the crew targeted U.S. defense contractors and financial services firms worldwide. In March 2018, security experts at Kaspersky Lab have observed an attack powered by the […]

    newssecurityaffairs.comJun 14, 2018, 6:23 AM
  • A China-linked cyber espionage group has targeted a national data center in Central Asia and experts believe the goal is to conduct watering hole attacks on the country’s government websites.

    newswww.securityweek.comJun 13, 2018, 2:54 PM
  • Fortinet recently observed a series of cyber-attacks targeting Russian service centers offering maintenance and support for various electronic goods. Security researchers from Fortinet have recently spotted a series of cyber-attacks targeting Russian service centers offering maintenance and support for various electronic goods. Experts highlighted the hackers conducted multi-stage attacks but excluded the involvement of a nation-state […]

    newssecurityaffairs.comJun 12, 2018, 7:11 AM
  • Fortinet security researchers recently observed a series of cyber-attacks targeting Russian service centers offering maintenance and support for various electronic goods.

    newswww.securityweek.comJun 11, 2018, 3:53 PM
  • Security experts at Trend Micro have spotted spam campaigns delivering XTRAT and DUNIHI Backdoors and Loki malware bundled with the Adwind RAT. Malware researchers at Trend Micro have uncovered a spam campaign that delivers the infamous Adwind RAT (aka jRAT) alongside the XTRAT backdoor (aka XtremeRAT) and the Loki info stealer. In a separate Adwind RAT spam campaign, the researchers observed the use […]

    newssecurityaffairs.comApr 22, 2018, 1:57 PM
  • Security researchers discovered a new Android Remote Access Trojan (RAT) dubbed KevDroid that can steal private data and record phone calls. Security researchers at South Korean cybersecurity firm ESTsecurity have discovered a new strain of Android Trojan KevDroid that is being distributed disguised as a fake anti-virus application, dubbed “Naver Defender.” “Spear phishing attacks targeting Android […]

    newssecurityaffairs.comApr 4, 2018, 10:54 AM
  • Security researchers have discovered a new Android Remote Access Trojan (RAT) that can steal a great deal of information from infected devices.

    newswww.securityweek.comApr 3, 2018, 6:30 PM
  • The China-linked APT group Leviathan. aka TEMP.Periscope, has increased the attacks on engineering and maritime entities over the past months. Past attacks conducted by the group aimed at targets connected to South China Sea issues, most of them were research institutes, academic organizations, and private firms in the United States. The group has also targeted professional/consulting services, high-tech industry, […]

    newssecurityaffairs.comMar 17, 2018, 4:49 PM
  • A China-related cyberespionage group that has been active for half a decade has increased its attacks on engineering and maritime entities over the past months, FireEye reports.

    newswww.securityweek.comMar 16, 2018, 8:36 PM
  • Unit 42 dives into the technical inner-workings of Hancitor’s latest malware packer.

    vendorunit42.paloaltonetworks.comFeb 27, 2018, 1:00 PM
  • Security researchers at Trustwave spotted a new malicious campaign that uses a multi-stage attack to deploy a password stealer. Researchers at Trustwave have spotted a new malware-based campaign that uses a multi-stage infection to deploy a password stealer malware. Hackers leverage the infamous Necurs botnet to distribute spam emails delivering Microsoft Office documents that embedded malicious macros. DOCX […]

    newssecurityaffairs.comFeb 20, 2018, 9:05 AM
  • A malicious attack uses a multi-stage infection to deploy malware that is capable of stealing passwords from various applications on a victim’s computer, Trustwave reports.

    newswww.securityweek.comFeb 19, 2018, 6:27 PM
  • Unit 42 examines CVE-2017-11882 and how Traps advanced endpoint protection protects against this threat.

    vendorunit42.paloaltonetworks.comJan 19, 2018, 9:00 PM
  • Security experts from FireEye have spotted a new strain of the Zyklon malware that has been delivered by using new vulnerabilities in Microsoft Office. Researchers at FireEye reported the malware was used in attacks against organizations in the telecommunications, financial, and insurance sectors. Zyklon has been spotted for the first time in 2016, it is a publicly available […]

    newssecurityaffairs.comJan 18, 2018, 9:19 AM
  • A piece of malware known as Zyklon has been delivered by cybercriminals using some relatively new vulnerabilities in Microsoft Office, FireEye reported on Wednesday.

    newswww.securityweek.comJan 17, 2018, 7:32 PM
  • As part of the January 2018 Patch Tuesday, Microsoft has released fixes for 56 CVE-listed vulnerabilities, including the Meltdown and Spectre flaws, and an Office bug actively exploited by attackers. Office flaw exploited in the wild Security updates and patches for mitigating the risk of Meltdown and Spectre attacks have received much attention in the past days, but those released by Microsoft on Tuesday also deserve it. As mentioned earlier, a flaw (CVE-2018-0802) in Microsoft … More →

    newswww.helpnetsecurity.comJan 10, 2018, 8:51 PM
  • Microsoft has released the January 2018 Patch Tuesday security updates, containing fixes for 56 vulnerabilities including the zero-day vulnerability CVE-2018-0802 in MS Office. Microsoft has released the January 2018 Patch Tuesday security updates, containing fixes for 56 vulnerabilities including a zero-day vulnerability in MS Office. 16 security updates are rated as critical, 38 as important, 1 […]

    newssecurityaffairs.comJan 10, 2018, 8:05 AM
  • Microsoft’s January 2018 Patch Tuesday updates address more than 50 vulnerabilities, including a zero-day vulnerability in Office related to an Equation Editor flaw that has been exploited by several threat groups in the past few months.

    newswww.securityweek.comJan 9, 2018, 8:33 PM
  • Research By: Omer Gull and Netanel Ben Simon Background A few weeks ago, a vulnerability in the Office Equation 3.0 process (EQNEDT32.EXE) was discovered by Embedi. For a couple of reasons this event raised a few eyebrows. First, the process was a 32bit application without ASLR even on a windows 10 machine. Secondly, the […]

    vendorresearch.checkpoint.comJan 9, 2018, 6:38 PM
  • A recently discovered Remote Access Trojan (RAT) is being distributed via documents that exploit

    newswww.securityweek.comDec 19, 2017, 2:38 PM
  • Unit 42 analyses multiple instances of threat actors exploiting critical vulnerability CVE-2017-11882.

    vendorunit42.paloaltonetworks.comDec 8, 2017, 1:00 PM
  • A cyber espionage group linked to Iran has been using a recently patched Microsoft Office vulnerability to deliver malware to targeted organizations, FireEye reported on Thursday.

    newswww.securityweek.comDec 7, 2017, 6:41 PM
  • A new round of the weekly SecurityAffairs newsletter arrived! The best news of the week with Security Affairs. Once again thank you! · A new Mirai variant is rapidly spreading, around 100,000 IPs running the scans in the past 60 hours · Security Affairs newsletter Round 138 – News of the week · The Cobalt […]

    newssecurityaffairs.comDec 3, 2017, 1:38 PM
  • The notorious Cobalt hacking group has started to exploit a 17-year-old vulnerability in Microsoft Office that was addressed earlier this month, security researchers claim.

    newswww.securityweek.comNov 27, 2017, 6:40 PM
  • A few days after details about the CVE-2017-11882 Microsoft Office flaw were publicly disclosed, the firm Reversing Lab observed Cobalt group using it. A few days after details about the CVE-2017-11882 Microsoft Office vulnerability were publicly disclosed, security experts from firm Reversing Lab observed criminal gang using it in the wild. The gang is the notorious Cobalt hacking group […]

    newssecurityaffairs.comNov 26, 2017, 2:06 PM
  • CC/CERT is warning the Address Space Layout Randomisation (ASLR) isn’t properly implemented in versions of Microsoft Windows 8 and newer. The researcher Will Dormann from the Carnegie-Mellon CERT has discovered the Address Space Layout Randomisation (ASLR) isn’t properly implemented in versions of Microsoft Windows 8 and newer. Actually, with Windows 7 and EMET System-wide ASLR, the loaded […]

    newssecurityaffairs.comNov 21, 2017, 8:30 AM
  • Microsoft engineers appear to have manually patched a 17 year-old vulnerability in Office , instead of altering the source code of the vulnerable component, ACROS Security researchers say.

    newswww.securityweek.comNov 20, 2017, 3:25 PM
  • A new round of the weekly SecurityAffairs newsletter arrived! The best news of the week with Security Affairs. Once again thank you! · Avira spotted a new strain of the dreaded Locky Ransomware in the wild · Google introduces updates in Chrome to prevent unexpected redirects and unwanted content · Microsoft president urges a digital […]

    newssecurityaffairs.comNov 19, 2017, 9:27 AM
  • Microsoft on Tuesday released its November 2017 security updates to resolve 53 vulnerabilities across products , including a security bug that has impacted all versions of its Microsoft Office suite over the past 17 years.

    newswww.securityweek.comNov 15, 2017, 5:12 PM
  • Ops, a 17-Year-Old flaw in MS Office, tracked as CVE-2017-11882, could be exploited by remote attackers to install a malware without user interaction. Ops, a 17-Year-Old vulnerability in MS Office could be exploited by remote attackers to install a malware without user interaction. The flaw is a memory-corruption issue that affects all versions of Microsoft […]

    newssecurityaffairs.comNov 15, 2017, 12:30 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence