CISA KEV · catalog date Mar 3, 2022 · first observed Jul 19, 2026
Evidence dossier
CVE-2017-11826
Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word Viewer, Word 2007, 2010, 2013 and…
Exploited in the wild (CISA KEV since Mar 3, 2022). NVD reports CVSS 3.1 7.8. EPSS estimates 81.5% exploit likelihood as of Aug 27, 2026.
As of Aug 27, 2026
Normalized restatement
Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word Viewer, Word 2007, 2010, 2013 and 2016, Word Automation Services, and Office Online Server allow remote code execution when the software fails to properly handle objects in memory.
- State
- PUBLISHED
- Published
- Oct 13, 2017
- Updated
- Oct 21, 2025
- Evidence coverage
- 98%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateSource date omittedFirst observed by CASCAmicrosoftOriginal evidence ↗
Record text: Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word Viewer, Word 2007, 2010, 2013 and 2016, Word Automation Services, and Office Online Server allow remote code execution when the software fails to properly handle objects in memory.
Inspect raw assertion
- Field
container- Value
- Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word Viewer, Word 2007, 2010, 2013 and 2016, Word Automation Services, and Office Online Server allow remote code execution when the software fails to properly handle objects in memory.
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: Microsoft Office Remote Code Execution Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Microsoft Office Remote Code Execution Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 81.45% probability · 99.61th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.814540000000; percentile 0.996110000000
FIRST EPSS · score date Aug 27, 2026 · 99.6th percentile · first observed Aug 27, 2026
NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
casca-unknown-reasons-v1Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- casca-direct-cvss-eligibility-v1
- Cutoff
- Aug 27, 2026
- Resolution
- None
The cited source assertion is retained while canonical product linkage remains open.
- Revision
- casca-factor-d-obligations-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve identity
Source comparison
Who said what
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word Viewer, Word 2007, 2010, 2013 and 2016, Word Automation Services, and Office Online Server allow remote code execution when the software fails to properly handle objects in memory.
Inspect raw assertion
- Field
container- Value
- Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word Viewer, Word 2007, 2010, 2013 and 2016, Word Automation Services, and Office Online Server allow remote code execution when the software fails to properly handle objects in memory.
Microsoft Office Remote Code Execution Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Microsoft Office Remote Code Execution Vulnerability
81.45% probability · 99.61th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.814540000000; percentile 0.996110000000
Applicability
Cited product scope
Grouped from 1 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
8 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word Viewer, Word 2007, 2010, 2013 and 2016, Word Automation Services, Office Online Server."}]product-fe758137686484ffb07abeab90c90f69f48242b9bb56d3d0eb99f12d1ca3aa5dLinked exactInspect raw assertion
cpe:2.3:a:microsoft:office_compatibility_pack:-:sp3:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
71af058a-2e5d-4b11-88db-8903c64b13c1
product-bc7158cb1e3644ef2ae6a6cfb1571aba080b3af427bc7c86938573cb6c946e54Linked exactInspect raw assertion
cpe:2.3:a:microsoft:office_online_server:2016:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c6c0bd17-4324-4dff-9804-1825c4c182a1
product-9031f0ffd040ce5525e1c902af8c5bdb15303ebaa539f0ec2331e4618f5c47c1Linked exactInspect raw assertions
cpe:2.3:a:microsoft:office_web_apps_server:2010:sp2:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
84149df3-54ba-4738-9386-6c29b4e9448f
cpe:2.3:a:microsoft:office_web_apps_server:2013:sp1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
941b16a2-931d-4031-a016-5ea60e87be20
product-d4961dfd8a4399733262c3c8374d834756c5c17f84bd52de66db3993629d4b40Linked exactInspect raw assertion
cpe:2.3:a:microsoft:office_word_viewer:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c64b2636-8f96-48ba-921f-a8fa0e62de63
product-81bbbbe8a69dacc8bf68626ae50993d4e7c4532234dc81fc9c5362c8fcf4a91dLinked exactInspect raw assertion
cpe:2.3:a:microsoft:sharepoint_enterprise_server:2016:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9c082cc4-6128-475d-bc19-b239e348fdb2
product-77f9def9702aa8ece74aa62c4de32bc72b167cb6f10f2eff44492cf46afc2e03Linked exactInspect raw assertions
cpe:2.3:a:microsoft:sharepoint_server:2010:sp2:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9a57c675-05a9-4bc2-ae95-7ca5ca6b1f73
cpe:2.3:a:microsoft:sharepoint_server:2013:sp1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 7
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
16f33176-442c-4eff-8ea0-c640d203b939
product-c8093d22ed2cea792c0cc0ce039b1c82530e9d7a56e9ab1184596470080024c2Linked exactInspect raw assertions
cpe:2.3:a:microsoft:word:2010:sp2:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 9
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
24eedad9-9656-4b21-82e4-d60b83777492
cpe:2.3:a:microsoft:word:2007:sp3:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 8
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7d006508-bfb0-4f21-a361-3da644f51d8a
cpe:2.3:a:microsoft:word:2013:sp1:*:*:rt:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 11
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
45e21528-4b0f-4a6f-82ad-df7fdbf67c8f
cpe:2.3:a:microsoft:word:2016:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 12
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
4da042d4-b14e-4ddf-8423-dfb255679efe
cpe:2.3:a:microsoft:word:2013:sp1:*:*:-:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 10
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d7a48e44-f01a-40ad-b8af-8fe368248003
Affected-product evidence
Accepted scope and product mapping
7 canonical links · 1 source-reported links
vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-77f9def9702aa8ece74aa62c4de32bc72b167cb6f10f2eff44492cf46afc2e03
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
1aec9e41-fd17-4803-a40a-6c4ba71e9d2d4b6811a3-bf62-436d-a875-5756fd50b36cvendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-81bbbbe8a69dacc8bf68626ae50993d4e7c4532234dc81fc9c5362c8fcf4a91d
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
93bdc6d4-c0ea-4562-a5d5-aabdfb3871b3vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-9031f0ffd040ce5525e1c902af8c5bdb15303ebaa539f0ec2331e4618f5c47c1
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
1cd52ab0-c7a1-463c-a986-310534dd2a98a428e41d-94d7-48a1-b688-c1d61412179evendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-bc7158cb1e3644ef2ae6a6cfb1571aba080b3af427bc7c86938573cb6c946e54
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
b3f343ac-0983-48b1-a058-93f58a0eede2vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-c8093d22ed2cea792c0cc0ce039b1c82530e9d7a56e9ab1184596470080024c2
- Source class
- Nvd cpe vulnerable target
- Assertions
- 5
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
2290f493-fb1c-4a4a-99fd-5f5454fc6cd259fbe21a-22c8-4491-ab6e-274fb54b227f88c086d3-3490-4316-9d5e-de9d02b2bf74cad97c75-f11f-446b-94a7-1215a227ac4fe932b1ca-4246-41bc-87cf-11b3e4fb20b3vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-d4961dfd8a4399733262c3c8374d834756c5c17f84bd52de66db3993629d4b40
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
c9b78384-22b5-4cf0-95d1-2c834f5f4d00vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-fe758137686484ffb07abeab90c90f69f48242b9bb56d3d0eb99f12d1ca3aa5d
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
4376c1aa-7edb-4da9-8765-dcbb2f677264Canonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Direct cve affected
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
f260c509-7650-4fee-a24b-213d8b8985f6Assessments
CVSS by origin
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HAV:N/AC:M/Au:N/C:C/I:C/A:CCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HDirect CVE/CNA normalized decisions
CISA-ADP
CVSS 3.1 · Secondary · Independent enrichment · rank 2
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H- Validation
- Valid match
- Recomputed
- 7.8
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
Assessments are retained side by side under closed precedence. Cascade never averages CVSS.
Evidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.