CVE-2017-0199
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, Windows 8.1 allow remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office/WordPad Remote Code Execution Vulnerability w/Windows API."
- Published Apr 12, 2017
- CVSS 7.8 high
- 99.5% chance of exploitation in the next 30 days (EPSS)
- In CISA's Known Exploited Vulnerabilities catalog
- A Metasploit module exploits it
- A fix is available
Affected software
In the news
- Exploits and vulnerabilities in Q2 2026 Securelist ·
- APT and financial attacks on industrial organizations in Q4 2025 Kaspersky ICS CERT ·