Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0261 and CVE-2017-0281.
No PoCs from references.
- https://github.com/ARPSyndicate/cvemon
- https://github.com/Ostorlab/KEV
- https://github.com/Ostorlab/known_exploited_vulnerbilities_detectors
- https://github.com/Panopticon-Project/panopticon-APT28
- https://github.com/Panopticon-Project/panopticon-FancyBear
- https://github.com/cnhouzi/APTNotes
- https://github.com/houjingyi233/office-exploit-case-study
- https://github.com/qiantu88/office-cve