CVE-2018-0802

ENISA EUVD: EUVD-2018-1608 ↗
Exploited in the Wild ✓ Confirmed 0-Day ★ Google Project Zero
Triaged: March 5, 2026 3 articles Published: 2018-01-10

EPSS Score

Source: FIRST.org · 2026-05-23
93.89%
probability
This CVE has a 93.89% probability of being exploited in the next 30 days.
0% Top 99.9th percentile of all CVEs 100%

CVSS v3.1

Source: VulnerabilityLookup (CIRCL)
7.8
HIGH
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVSS v2 (legacy)

9.3
HIGH
Access Vector
Network
Access Complexity
Medium
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
AV:N/AC:M/Au:N/C:C/I:C/A:C

Description

VulnerabilityLookup (CNA)
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE is unique from CVE-2018-0797 and CVE-2018-0812.

Affected Products

Microsoft Corporation
Equation Editor
Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016

Attack Intelligence

Google Project Zero

Patched
Jan. 9, 2018
Reported by
Liang Yin of Tencent PC Manager, Zhiyuan Zheng, Yuki Chen of Qihoo 360 Vulcan Team, Yang Kang, Ding Maoyin and Song Shenlei, and Jinquan of Qihoo 360 Core Security (@360CoreSec), Luka Treiber of 0patch Team - ACROS Security, zhouat of Qihoo 360 Vulcan Team, bee13oy of Qihoo 360 Vulcan Team, Netanel Ben Simon and Omer Gull of Check Point Software Technologies
Root Cause Analysis
???

Exploits & PoC

rxwx/CVE-2018-0802

PoC Exploit for CVE-2018-0802 (and optionally CVE-2017-11882)

269 2018-02-28
Ridter/RTF_11882_0802

PoC for CVE-2018-0802 And CVE-2017-11882

166 2018-01-12
zldww2011/CVE-2018-0802_POC

Exploit the vulnerability to execute the calculator

68 2018-01-11
Abdibimantara/Maldoc-Analysis

Pada bulan maret 2023, terdapat sample baru yang terindentifikasi sebagai malware. Malware tersebut berasal dari file berekstensi.xls dan .doc dan dik

1 2023-03-06
6 repos — triés par ⭐ Rechercher sur GitHub ↗

Signal Intelligence

Confidence
95%
EPSS 93.89%
CVSS v3.1 7.8
Mentions 3
Last Seen Sep 04, 2023

CNA Information

CNA Assigner
microsoft

Analyst Note

Auto-imported from Google Project Zero — confirmed zero-day by definition.

Threat Actors 31

Lazarus Group
apt_group Information theft and espionage 🇰🇵 KP
Cobalt
apt_group Financial crime 🇷🇺 RU
GOLD SOUTHFIELD
apt_group Financial gain 🇷🇺 RU
Harvester
apt_group Information theft and espionage Unknown
Careto
apt_group Information theft and espionage 🇪🇸 ES
Leviathan
apt_group Information theft and espionage 🇨🇳 CN
Hacking Team
apt_group 🇮🇹 IT
FusionCore
apt_group 🇪🇺 EU
DNSpionage
apt_group Information theft and espionage 🇮🇷 IR
HAZY TIGER
apt_group Information theft and espionage 🇮🇳 IN
Equation Group
apt_group Sabotage and destruction 🇺🇸 US
Infy
apt_group Information theft and espionage 🇮🇷 IR
Group 27
apt_group Information theft and espionage 🇨🇳 CN
Gorilla
apt_group null
Inception Framework
apt_group Information theft and espionage 🇷🇺 RU
Lucky Cat
apt_group Information theft and espionage 🇨🇳 CN
TA428
apt_group Information theft and espionage 🇨🇳 CN
Pirate Panda
apt_group Information theft and espionage 🇨🇳 CN
TA413
apt_group Information theft and espionage 🇨🇳 CN
Inception
apt_group Information theft and espionage 🇷🇺 RU
PhantomCore
apt_group 🇷🇺 RU
APT 22
apt_group Information theft and espionage 🇨🇳 CN
Operation Cobalt Whisper
apt_group Financial crime 🇨🇳 CN
Webworm
apt_group Information theft and espionage 🇨🇳 CN
RedAlpha
apt_group Information theft and espionage 🇨🇳 CN
APT 6
apt_group Information theft and espionage 🇨🇳 CN
Tonto Team
apt_group Information theft and espionage 🇨🇳 CN
RANCOR
apt_group Information theft and espionage 🇨🇳 CN
Red October
apt_group 🇷🇺 RU
ToddyCat
apt_group Information theft and espionage 🇨🇳 CN
Mana Team
apt_group 🇨🇳 CN

Triage Info

Decided atMar 05, 2026
Published DateJan 10, 2018