RaqibCTI
CVE

CVE-2017-0199

P1⬤ KNOWN RANSOMWARE USE
Microsoft Office and WordPad Remote Code Execution Vulnerability
Microsoft · Office and WordPad
Date added (CISA)
2021-11-03
Remediation due
2022-05-03
Known ransomware use
Yes
Remediation priority
P1known ransomware use · past CISA due date
Associated with
Related to
  • Lazarus Group (TraderTraitor cluster) / APT38 / BlueNoroff · SPECTREcampaignCorrelated cluster2026-09-16
  • BadIIScampaignCorrelated cluster2026-08-26
  • Lazarus Group (TraderTraitor cluster) / APT38 / BlueNoroff · ZshBucketcampaignCorrelated cluster2026-08-26

Description

Microsoft Office and WordPad contain an unspecified vulnerability due to the way the applications parse specially crafted files. Successful exploitation allows for remote code execution.

Source: NVD ↗ · CISA KEV Catalog ↗

CVE-2017-0199: Microsoft Office and WordPad Remote Code Execution Vulnerability · RaqibCTI