Skip to main content
Patient Protect circular logo mark in purple and white used for site navigationPatient Protect
← The Naughty List

CVE-2017-11882 affecting Microsoft Office (+13 related CVEs)

CRITICALActively exploited by attackers

What to do

Apply the vendor-fixed release or documented mitigation as a priority; this vulnerability is known to be exploited.

Vendor
Microsoft
Product
Microsoft Office
Affected versions
Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016
First published
2026-08-30

Where this comes from

43 sources
  • FIRSTClass B

    FIRST EPSS exploitation probability

  • KEVClass A

    Vulnerability is exploited in the wild (CISA KEV listing)

  • FIRSTClass B

    FIRST EPSS exploitation probability

  • KEVClass A

    Vulnerability is exploited in the wild (CISA KEV listing)

  • KEVClass A

    Vulnerability is exploited in the wild (CISA KEV listing)

  • KEVClass A

    Vulnerability is exploited in the wild (CISA KEV listing)

  • KEVClass A

    Vulnerability is exploited in the wild (CISA KEV listing)

  • KEVClass A

    Vulnerability is exploited in the wild (CISA KEV listing)

  • FIRSTClass B

    FIRST EPSS exploitation probability

  • FIRSTClass B

    FIRST EPSS exploitation probability

  • FIRSTClass B

    FIRST EPSS exploitation probability

  • FIRSTClass B

    FIRST EPSS exploitation probability

  • KEVClass A

    Vulnerability is exploited in the wild (CISA KEV listing)

  • FIRSTClass B

    FIRST EPSS exploitation probability

  • KEVClass A

    Vulnerability is exploited in the wild (CISA KEV listing)

  • KEVClass A

    Vulnerability is exploited in the wild (CISA KEV listing)

  • KEVClass A

    Vulnerability is exploited in the wild (CISA KEV listing)

  • KEVClass A

    Vulnerability is exploited in the wild (CISA KEV listing)

  • KEVClass A

    Vulnerability is exploited in the wild (CISA KEV listing)

  • FIRSTClass B

    FIRST EPSS exploitation probability

  • CNAClass A

    CNA-published affected versions and remediation

  • KEVClass A

    Vulnerability is exploited in the wild (CISA KEV listing)

  • FIRSTClass B

    FIRST EPSS exploitation probability

  • KEVClass A

    Vulnerability is exploited in the wild (CISA KEV listing)

  • KEVClass A

    Vulnerability is exploited in the wild (CISA KEV listing)

  • FIRSTClass B

    FIRST EPSS exploitation probability

  • KEVClass A

    Vulnerability is exploited in the wild (CISA KEV listing)

  • FIRSTClass B

    FIRST EPSS exploitation probability

  • KEVClass A

    Vulnerability is exploited in the wild (CISA KEV listing)

  • KEVClass A

    Vulnerability is exploited in the wild (CISA KEV listing)

  • KEVClass A

    Vulnerability is exploited in the wild (CISA KEV listing)

  • FIRSTClass B

    FIRST EPSS exploitation probability

  • KEVClass A

    Vulnerability is exploited in the wild (CISA KEV listing)

  • KEVClass A

    Vulnerability is exploited in the wild (CISA KEV listing)

  • FIRSTClass B

    FIRST EPSS exploitation probability

  • KEVClass A

    Vulnerability is exploited in the wild (CISA KEV listing)

  • KEVClass A

    Vulnerability is exploited in the wild (CISA KEV listing)

  • KEVClass A

    Vulnerability is exploited in the wild (CISA KEV listing)

  • KEVClass A

    Vulnerability is exploited in the wild (CISA KEV listing)

  • KEVClass A

    Vulnerability is exploited in the wild (CISA KEV listing)

  • KEVClass A

    Vulnerability is exploited in the wild (CISA KEV listing)

  • KEVClass A

    Vulnerability is exploited in the wild (CISA KEV listing)

  • FIRSTClass B

    FIRST EPSS exploitation probability

How this was assessed

  • CVE-2017-11882 triggered rule KEV_KNOWN_EXPLOITED
  • CISA KEV lists it as known-exploited
  • EPSS 0.99945
  • Microsoft Office affected range confirmed by CNA
  • Patient Protect score 75.99 (CRITICAL) under pp-risk-1.0
  • remediation provenance: PP_TEMPLATE
  • evidence sufficient

Information provided by Patient Protect's Technology Risk Ledger (“The Naughty List”) is sourced from official vendor and government advisories and is provided “as is” for informational purposes only. Inclusion on The Naughty List identifies a documented technology-security risk based on available evidence at the time of publication; it is not a finding of wrongdoing, negligence, or fault by any vendor. Patient Protect does not warrant the completeness, accuracy, or timeliness of the information. Users are solely responsible for verifying applicability to their specific environment and for their own remediation decisions. Patient Protect disclaims all liability for damages arising from the use of this information.

Do you run this?

Check your own version against the ledger — it may or may not fall inside the affected range.

Check your technology