CVE-2017-0199

ENISA EUVD: EUVD-2017-0566 ↗
Exploited in the Wild ✓ Confirmed 0-Day ★ Google Project Zero
Triaged: March 3, 2026 9 articles

EPSS Score

Source: FIRST.org · 2026-05-24
94.3%
probability
This CVE has a 94.3% probability of being exploited in the next 30 days.
0% Top 99.9th percentile of all CVEs 100%

CVSS v3.1

Source: NVD
7.8
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Description

Project Zero
Logic/design flaw in embedded HTA documents

Affected Products

Google Project Zero

Patched
April 11, 2017
Reported by
Ryan Hanson (@Ryhanson) of Optiv, Microsoft MSRC Vulnerabilities and Mitigations Team, Microsoft Office Security Team, Genwei Jiang, FLARE Team, FireEye Inc, Eduardo Braun Prado of SecuriTeam Secure Disclosure (SSD)
Root Cause Analysis
???

Exploits & PoC

bhdresh/CVE-2017-0199

Exploit toolkit CVE-2017-0199 - v4.0 is a handy python script which provides pentesters and security researchers a quick and effective way to test Mic

726
Exploit-install/CVE-2017-0199

Exploit toolkit CVE-2017-0199 - v2.0 is a handy python script which provides a quick and effective way to exploit Microsoft RTF RCE. It could generate

7
jacobsoo/RTF-Cleaner

RTF Cleaner, tries to extract URL from malicious RTF samples using CVE-2017-0199 & CVE-2017-8759

3
nicpenning/RTF-Cleaner

RTF de-obfuscator for CVE-2017-0199 documents to find URLs statically.

3
kn0wm4d/htattack

An exploit implementation for RCE in RTF & DOCs (CVE-2017-0199)

2
mzakyz666/PoC-CVE-2017-0199

Exploit toolkit for vulnerability RCE Microsoft RTF

2
n1shant-sinha/CVE-2017-0199

Exploit toolkit CVE-2017-0199 - v2.0 is a handy python script which provides a quick and effective way to exploit Microsoft RTF RCE. It could generate

2
8 repos — triés par ⭐ Rechercher sur GitHub ↗

Signal Intelligence

Confidence
92%
EPSS 94.3%
CVSS v3.1 7.8
Mentions 9
Last Seen May 27, 2026

CNA Information

Analyst Note

CVE-2017-0199 is a well-documented remote code execution vulnerability in Microsoft Office affecting multiple versions across Windows platforms, with CVSS 7.8 (HIGH) severity. The vulnerability was reported by Google Project Zero and actively exploited in the wild according to CERT-EU security advisories, providing strong evidence for confirmation.

Threat Actors 49

MuddyWater
apt_group Information theft and espionage 🇮🇷 IR
Lazarus Group
apt_group Information theft and espionage 🇰🇵 KP
Turla Group
apt_group Information theft and espionage Russian Federation
APT37
apt_group Information theft and espionage 🇰🇵 KP
APT 28
apt_group Information theft and espionage 🇷🇺 RU
FIN7
apt_group Financial crime 🇷🇺 RU
Kimsuky
apt_group Information theft and espionage 🇰🇷 KR
CHRYSENE
apt_group Information theft and espionage 🇮🇷 IR
Harvester
apt_group Information theft and espionage Unknown
Careto
apt_group Information theft and espionage 🇪🇸 ES
Leviathan
apt_group Information theft and espionage 🇨🇳 CN
FusionCore
apt_group 🇪🇺 EU
Ice Fog
apt_group Information theft and espionage 🇨🇳 CN
GOLD PRELUDE
apt_group 🇷🇺 RU
DNSpionage
apt_group Information theft and espionage 🇮🇷 IR
Kinsing
apt_group 🇷🇺 RU
Gamaredon Group
apt_group Information theft and espionage 🇷🇺 RU
Mirage
apt_group Information theft and espionage 🇨🇳 CN
Equation Group
apt_group Sabotage and destruction 🇺🇸 US
Naikon
apt_group Information theft and espionage 🇨🇳 CN
SideCopy
apt_group Information theft and espionage 🇵🇰 PK
Group 27
apt_group Information theft and espionage 🇨🇳 CN
TeamTNT
apt_group 🇩🇪 DE
HomeLand Justice
apt_group Sabotage and destruction 🇮🇷 IR
Camaro Dragon
apt_group Information theft and espionage 🇨🇳 CN
TA428
apt_group Information theft and espionage 🇨🇳 CN
GhostR
apt_group 🇨🇳 CN
Comment Crew
apt_group Information theft and espionage 🇨🇳 CN
SideWinder
apt_group 🇮🇳 IN
LUNAR SPIDER
apt_group 🇷🇺 RU
Void Manticore
apt_group Sabotage and destruction 🇮🇷 IR
VICEROY TIGER
apt_group Information theft and espionage 🇮🇳 IN
RAZOR TIGER
apt_group Information theft and espionage 🇮🇳 IN
Tortoiseshell
apt_group Information theft and espionage 🇮🇷 IR
[Unnamed group]
apt_group 🇨🇳 CN
TA413
apt_group Information theft and espionage 🇨🇳 CN
TAG-28
apt_group Information theft and espionage 🇨🇳 CN
TA558
apt_group Financial crime 🇧🇷 BR
Hurricane Panda
apt_group Information theft and espionage 🇨🇳 CN
APT 22
apt_group Information theft and espionage 🇨🇳 CN
Operation Cobalt Whisper
apt_group Financial crime 🇨🇳 CN
APT 6
apt_group Information theft and espionage 🇨🇳 CN
RevengeHotels
apt_group Information theft and espionage 🇧🇷 BR
RANCOR
apt_group Information theft and espionage 🇨🇳 CN
Pat Bear
apt_group 🇸🇾 SY
Operation Red Signature
apt_group Information theft and espionage 🇨🇳 CN
Mana Team
apt_group 🇨🇳 CN
Scarred Manticore
apt_group Information theft and espionage 🇮🇷 IR
APT 5
apt_group Information theft and espionage 🇨🇳 CN

Triage Info

Decided atMar 03, 2026