CVE-2017-11826: Microsoft Office Remote Code Execution Vulnerability

High severity, CVSS 7.8. Actively exploited: in CISA KEV since 2022-03-03. EPSS: 81.2% chance of exploitation in the next 30 days.

Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word Viewer, Word 2007, 2010, 2013 and 2016, Word Automation Services, and Office Online Server allow remote code execution when the software fails to properly handle objects in memory.

Affected products

  • Microsoft Office Compatibility Pack: affected versions not specified
  • Microsoft Office Online Server: version 2016 only
  • Microsoft Office Web Apps Server: version 2010 only; version 2013 only
  • Microsoft Office Word Viewer: affected versions not specified
  • Microsoft SharePoint Enterprise Server: version 2016 only
  • Microsoft SharePoint Server: version 2010 only; version 2013 only
  • Microsoft Word: version 2007 only; version 2010 only; version 2013 only; version 2016 only

Published 2017-10-13. Last modified 2026-06-17.