CVE-2018-0802

ENISA EUVD: EUVD-2018-1608 ↗
Exploited in the Wild ✓ Confirmed 0-Day ★ Google Project Zero
Triaged: March 5, 2026 3 articles

EPSS Score

Source: FIRST.org · 2026-05-24
93.89%
probability
This CVE has a 93.89% probability of being exploited in the next 30 days.
0% Top 99.9th percentile of all CVEs 100%

CVSS v3.1

Source: NVD
7.8
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Description

Project Zero
Buffer overflow in equation editor lfFaceName

Affected Products

Attack Intelligence

Google Project Zero

Patched
Jan. 9, 2018
Reported by
Liang Yin of Tencent PC Manager, Zhiyuan Zheng, Yuki Chen of Qihoo 360 Vulcan Team, Yang Kang, Ding Maoyin and Song Shenlei, and Jinquan of Qihoo 360 Core Security (@360CoreSec), Luka Treiber of 0patch Team - ACROS Security, zhouat of Qihoo 360 Vulcan Team, bee13oy of Qihoo 360 Vulcan Team, Netanel Ben Simon and Omer Gull of Check Point Software Technologies
Root Cause Analysis
???

Exploits & PoC

rxwx/CVE-2018-0802

PoC Exploit for CVE-2018-0802 (and optionally CVE-2017-11882)

270
Ridter/RTF_11882_0802

PoC for CVE-2018-0802 And CVE-2017-11882

167
zldww2011/CVE-2018-0802_POC

Exploit the vulnerability to execute the calculator

68
likekabin/CVE-2018-0802_CVE-2017-11882

PoC CVE-2018-0802 — likekabin/CVE-2018-0802_CVE-2017-11882

11
roninAPT/CVE-2018-0802

PoC CVE-2018-0802 — roninAPT/CVE-2018-0802

0
5 repos — triés par ⭐ Rechercher sur GitHub ↗

Signal Intelligence

Confidence
95%
EPSS 93.89%
CVSS v3.1 7.8
Mentions 3
Last Seen Sep 04, 2023

CNA Information

Analyst Note

Auto-imported from Google Project Zero — confirmed zero-day by definition.

Threat Actors 31

Lazarus Group
apt_group Information theft and espionage 🇰🇵 KP
Cobalt
apt_group Financial crime 🇷🇺 RU
GOLD SOUTHFIELD
apt_group Financial gain 🇷🇺 RU
Harvester
apt_group Information theft and espionage Unknown
Careto
apt_group Information theft and espionage 🇪🇸 ES
Leviathan
apt_group Information theft and espionage 🇨🇳 CN
Hacking Team
apt_group 🇮🇹 IT
FusionCore
apt_group 🇪🇺 EU
DNSpionage
apt_group Information theft and espionage 🇮🇷 IR
HAZY TIGER
apt_group Information theft and espionage 🇮🇳 IN
Equation Group
apt_group Sabotage and destruction 🇺🇸 US
Infy
apt_group Information theft and espionage 🇮🇷 IR
Group 27
apt_group Information theft and espionage 🇨🇳 CN
Gorilla
apt_group null
Inception Framework
apt_group Information theft and espionage 🇷🇺 RU
Lucky Cat
apt_group Information theft and espionage 🇨🇳 CN
TA428
apt_group Information theft and espionage 🇨🇳 CN
Pirate Panda
apt_group Information theft and espionage 🇨🇳 CN
TA413
apt_group Information theft and espionage 🇨🇳 CN
Inception
apt_group Information theft and espionage 🇷🇺 RU
PhantomCore
apt_group 🇷🇺 RU
APT 22
apt_group Information theft and espionage 🇨🇳 CN
Operation Cobalt Whisper
apt_group Financial crime 🇨🇳 CN
Webworm
apt_group Information theft and espionage 🇨🇳 CN
RedAlpha
apt_group Information theft and espionage 🇨🇳 CN
APT 6
apt_group Information theft and espionage 🇨🇳 CN
Tonto Team
apt_group Information theft and espionage 🇨🇳 CN
RANCOR
apt_group Information theft and espionage 🇨🇳 CN
Red October
apt_group 🇷🇺 RU
ToddyCat
apt_group Information theft and espionage 🇨🇳 CN
Mana Team
apt_group 🇨🇳 CN

Triage Info

Decided atMar 05, 2026