CVE-2017-11882 is a Microsoft Office memory corruption flaw in the legacy Equation Editor that enables arbitrary code execution in the context of the current user when a victim opens a crafted document. The vulnerability affects Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, and Office 2016, and public exploit material quickly emerged showing how malicious RTF files could trigger remote command execution or shellcode execution, including Metasploit support and techniques that leveraged mshta.exe or injected payloads into EQNEDT32.EXE.
The flaw was also used in phishing operations to deliver malware. One documented campaign used malicious Office documents exploiting CVE-2017-11882 alongside CVE-2017-0199 to deploy the LokiBot stealer through a multi-stage chain involving encrypted Excel files, embedded OLE objects, and follow-on document retrieval. Investigation of the campaign exposed misconfigured attacker infrastructure, including a publicly accessible phpinfo.php page on 192.3.239.42, a host identified as WIN-2NF07F1AQLT, and OSINT links to additional infrastructure and Brazil-registered scam domains tied to the operation.

See real exploitation activity before you spend the cycle.
10 events from the most recent confirmed update back to the earliest known activity.
The CVE record for CVE-2017-11882 was updated, with the entry continuing to note advisory, CERT, exploit, and in-the-wild research references. The update did not change the core description of the Microsoft Office memory corruption flaw.
A GitHub repository published a proof of concept named webdav_exec for CVE-2017-11882 that generated a malicious document using OLE objects for sequential command execution. The technique used a UNC path and WebDAV to start the WebClient service and launch an attacker-controlled executable from a remote server, bypassing command-length limitations.
Trend Micro disclosed a malicious RTF document exploiting CVE-2017-11882 to launch an HTA file, invoke PowerShell, and retrieve the Loki spyware payload. The report also said other actors were using the flaw in spam campaigns to distribute malware including Pony/FAREIT, FormBook, ZLoader, and Ursnif.
A GitHub repository published a Metasploit module and RTF template for exploiting CVE-2017-11882, based on a public Embedi proof of concept. The module used mshta.exe to execute the payload.
Unit 42 reported active in-the-wild exploitation of CVE-2017-11882 and said that since November 20 it had seen thousands of attack attempts. The researchers described a Europe-targeted fake invoice campaign in which a malicious Office document used the flaw to launch mshta and ultimately download the FormBook information stealer.
CVE-2017-11882 was published as a Microsoft Office memory corruption vulnerability that can allow arbitrary code execution in the context of the current user. The record identifies affected Office versions including Office 2007 SP3, 2010 SP2, 2013 SP1, and 2016.
Microsoft published its Security Update Guide entry for CVE-2017-11882, describing a Microsoft Office memory corruption vulnerability that could lead to remote code execution when a user opens a specially crafted file. Microsoft said the flaw was not publicly disclosed or exploited at original publication and that the update fixed how the affected component handled objects in memory.
Investigation of the LokiBot campaign found a publicly accessible phpinfo.php page on 192.3.239.42 that exposed the hostname WIN-2NF07F1AQLT and a Windows Server 2016 environment. OSINT linked the hostname to additional malicious infrastructure and to Brazil-registered domains Webcamer.com.br and Citydesconto.com.br.
Researchers described a phishing campaign using malicious Office documents that exploited CVE-2017-0199 and CVE-2017-11882 to deliver the LokiBot stealer. The lure impersonated Romania's ANAF and led victims through a multi-stage chain ending with download of vbc.exe from attacker infrastructure.
A GitHub exploit repository documented a Python-based CVE-2017-11882 exploit that could generate crafted RTF files for command execution or shellcode delivery, supporting payloads of roughly 17 KB. The write-up also described optional shellcode injection into a new EQNEDT32.EXE process.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 81 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
13 references tracked. Mallory keeps watching after this page renders.
blog.trendmicro.com
Open sourcecve.mitre.org
Open sourcecve.mitre.org
Open sourcecybergeeks.tech
Open sourceexploit-db.com
Open sourcemsrc.microsoft.com
Open sourceblog.trendmicro.com
Open sourcecve.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.