🛡 CVE-2018-0802
Microsoft Office Memory Corruption Vulnerability
Microsoft Office CWE-787
Ransomware use
—
CISA KEV
EPSS
87.4%
Likely exploited · 100th pct
Added to KEV
2021-11-03
CISA
Remediate by
2022-05-03
⚠ OVERDUE
CWE
CWE-787
weakness
📈 EPSS exploit probability
87.4%
FIRST EPSS — 30-day probability of exploitation in the wild · band Likely exploited · higher than 100% of all scored CVEs
⚠ KEV remediation overdue
CISA required federal remediation by 2022-05-03. This exploited vulnerability is past its Binding Operational Directive 22-01 due date — prioritize patch/mitigation and hunt for exploitation.
📄 Description
Microsoft Office contains a memory corruption vulnerability due to the way objects are handled in memory. Successful exploitation allows for remote code execution in the context of the current user. This vulnerability is known to be chained
🔗 External references & OSINT
🔄 Internal pivots & actions
🛡 Add to case
🧩 Advanced Capabilities
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports
🤖 AI Copilot
⚡ AI Skills
🔍 Lookup & Enrich
📚 Docs & Reports
💡 Recommendations
- Explore related tools below
- Automate recurring work via cron