CVE-2017-0199
ENISA EUVD: EUVD-2017-0566 ↗
Exploited in the Wild
✓ Confirmed 0-Day
★ Google Project Zero
Triaged: March 3, 2026
9 articles
EPSS Score
Source: FIRST.org · 2026-05-24
94.3%
probability
This CVE has a 94.3% probability
of being exploited in the next 30 days.
0%
Top 99.9th percentile of all CVEs
100%
CVSS v3.1
Source: NVD7.8
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Description
Project ZeroLogic/design flaw in embedded HTA documents
Affected Products
Google Project Zero
Patched
April 11, 2017
Reported by
Ryan Hanson (@Ryhanson) of Optiv, Microsoft MSRC Vulnerabilities and Mitigations Team, Microsoft Office Security Team, Genwei Jiang, FLARE Team, FireEye Inc, Eduardo Braun Prado of SecuriTeam Secure Disclosure (SSD)
Root Cause Analysis
???
Exploits & PoC
bhdresh/CVE-2017-0199
Exploit toolkit CVE-2017-0199 - v4.0 is a handy python script which provides pentesters and security researchers a quick and effective way to test Mic
726
haibara3839/CVE-2017-0199-master
CVE-2017-0199
16
Exploit-install/CVE-2017-0199
Exploit toolkit CVE-2017-0199 - v2.0 is a handy python script which provides a quick and effective way to exploit Microsoft RTF RCE. It could generate
7
jacobsoo/RTF-Cleaner
RTF Cleaner, tries to extract URL from malicious RTF samples using CVE-2017-0199 & CVE-2017-8759
3
nicpenning/RTF-Cleaner
RTF de-obfuscator for CVE-2017-0199 documents to find URLs statically.
3
kn0wm4d/htattack
An exploit implementation for RCE in RTF & DOCs (CVE-2017-0199)
2
mzakyz666/PoC-CVE-2017-0199
Exploit toolkit for vulnerability RCE Microsoft RTF
2
n1shant-sinha/CVE-2017-0199
Exploit toolkit CVE-2017-0199 - v2.0 is a handy python script which provides a quick and effective way to exploit Microsoft RTF RCE. It could generate
2
8 repos — triés par ⭐
Rechercher sur GitHub ↗
Recent Microsoft 0-Day Used for Cyber-Espionage and Mundane Malware Distribution
BleepingComputer
Apr 13, 2017
Part 2: An In-Depth Look at the Latest Vulnerability Threat Landscape (Attackers’ Edition)
Qualys
Jul 18, 2023
Microsoft Fixes 45 Vulnerabilities with new Security Update Guide – says goodbye to Security Bulletins
Qualys
Apr 11, 2017
Qualys Top 20 Most Exploited Vulnerabilities
Qualys
Sep 04, 2023
Microsoft Office Zero-Day Used to Push Dridex Banking Trojan
BleepingComputer
Apr 11, 2017
Inside the customer environment: Where threat actors, vulnerabilities, and exposed assets intersect
Tenable-Research
May 27, 2026
Security Advisory 2017-009
CERT-EU
Apr 12, 2017
Signal Intelligence
Confidence
92%
EPSS
94.3%
CVSS v3.1
7.8
Mentions
9
Last Seen
May 27, 2026
CNA Information
Analyst Note
CVE-2017-0199 is a well-documented remote code execution vulnerability in Microsoft Office affecting multiple versions across Windows platforms, with CVSS 7.8 (HIGH) severity. The vulnerability was reported by Google Project Zero and actively exploited in the wild according to CERT-EU security advisories, providing strong evidence for confirmation.
Threat Actors 49
MuddyWater
apt_group
Information theft and espionage
🇮🇷 IR
Lazarus Group
apt_group
Information theft and espionage
🇰🇵 KP
Turla Group
apt_group
Information theft and espionage
Russian Federation
APT37
apt_group
Information theft and espionage
🇰🇵 KP
APT 28
apt_group
Information theft and espionage
🇷🇺 RU
FIN7
apt_group
Financial crime
🇷🇺 RU
Kimsuky
apt_group
Information theft and espionage
🇰🇷 KR
CHRYSENE
apt_group
Information theft and espionage
🇮🇷 IR
Harvester
apt_group
Information theft and espionage
Unknown
Careto
apt_group
Information theft and espionage
🇪🇸 ES
Leviathan
apt_group
Information theft and espionage
🇨🇳 CN
FusionCore
apt_group
🇪🇺 EU
Ice Fog
apt_group
Information theft and espionage
🇨🇳 CN
GOLD PRELUDE
apt_group
🇷🇺 RU
DNSpionage
apt_group
Information theft and espionage
🇮🇷 IR
Kinsing
apt_group
🇷🇺 RU
Gamaredon Group
apt_group
Information theft and espionage
🇷🇺 RU
Mirage
apt_group
Information theft and espionage
🇨🇳 CN
Equation Group
apt_group
Sabotage and destruction
🇺🇸 US
Naikon
apt_group
Information theft and espionage
🇨🇳 CN
SideCopy
apt_group
Information theft and espionage
🇵🇰 PK
Group 27
apt_group
Information theft and espionage
🇨🇳 CN
TeamTNT
apt_group
🇩🇪 DE
HomeLand Justice
apt_group
Sabotage and destruction
🇮🇷 IR
Camaro Dragon
apt_group
Information theft and espionage
🇨🇳 CN
TA428
apt_group
Information theft and espionage
🇨🇳 CN
GhostR
apt_group
🇨🇳 CN
Comment Crew
apt_group
Information theft and espionage
🇨🇳 CN
SideWinder
apt_group
🇮🇳 IN
LUNAR SPIDER
apt_group
🇷🇺 RU
Void Manticore
apt_group
Sabotage and destruction
🇮🇷 IR
VICEROY TIGER
apt_group
Information theft and espionage
🇮🇳 IN
RAZOR TIGER
apt_group
Information theft and espionage
🇮🇳 IN
Tortoiseshell
apt_group
Information theft and espionage
🇮🇷 IR
[Unnamed group]
apt_group
🇨🇳 CN
TA413
apt_group
Information theft and espionage
🇨🇳 CN
TAG-28
apt_group
Information theft and espionage
🇨🇳 CN
TA558
apt_group
Financial crime
🇧🇷 BR
Hurricane Panda
apt_group
Information theft and espionage
🇨🇳 CN
APT 22
apt_group
Information theft and espionage
🇨🇳 CN
Operation Cobalt Whisper
apt_group
Financial crime
🇨🇳 CN
APT 6
apt_group
Information theft and espionage
🇨🇳 CN
RevengeHotels
apt_group
Information theft and espionage
🇧🇷 BR
RANCOR
apt_group
Information theft and espionage
🇨🇳 CN
Pat Bear
apt_group
🇸🇾 SY
Operation Red Signature
apt_group
Information theft and espionage
🇨🇳 CN
Mana Team
apt_group
🇨🇳 CN
Scarred Manticore
apt_group
Information theft and espionage
🇮🇷 IR
APT 5
apt_group
Information theft and espionage
🇨🇳 CN
Triage Info
Decided atMar 03, 2026