CVE-2018-0802
ENISA EUVD: EUVD-2018-1608 ↗
Exploited in the Wild
✓ Confirmed 0-Day
★ Google Project Zero
Triaged: March 5, 2026
3 articles
EPSS Score
Source: FIRST.org · 2026-05-24
93.89%
probability
This CVE has a 93.89% probability
of being exploited in the next 30 days.
0%
Top 99.9th percentile of all CVEs
100%
CVSS v3.1
Source: NVD7.8
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Description
Project ZeroBuffer overflow in equation editor lfFaceName
Affected Products
Attack Intelligence
Google Project Zero
Patched
Jan. 9, 2018
Reported by
Liang Yin of Tencent PC Manager, Zhiyuan Zheng, Yuki Chen of Qihoo 360 Vulcan Team, Yang Kang, Ding Maoyin and Song Shenlei, and Jinquan of Qihoo 360 Core Security (@360CoreSec), Luka Treiber of 0patch Team - ACROS Security, zhouat of Qihoo 360 Vulcan Team, bee13oy of Qihoo 360 Vulcan Team, Netanel Ben Simon and Omer Gull of Check Point Software Technologies
Root Cause Analysis
???
Exploits & PoC
rxwx/CVE-2018-0802
PoC Exploit for CVE-2018-0802 (and optionally CVE-2017-11882)
270
Ridter/RTF_11882_0802
PoC for CVE-2018-0802 And CVE-2017-11882
167
zldww2011/CVE-2018-0802_POC
Exploit the vulnerability to execute the calculator
68
likekabin/CVE-2018-0802_CVE-2017-11882
PoC CVE-2018-0802 — likekabin/CVE-2018-0802_CVE-2017-11882
11
roninAPT/CVE-2018-0802
PoC CVE-2018-0802 — roninAPT/CVE-2018-0802
0
5 repos — triés par ⭐
Rechercher sur GitHub ↗
Part 2: An In-Depth Look at the Latest Vulnerability Threat Landscape (Attackers’ Edition)
Qualys
Jul 18, 2023
Qualys Top 20 Most Exploited Vulnerabilities
Qualys
Sep 04, 2023
Microsoft January Patch Tuesday Fixes 56 Security Issues, Including a Zero-Day
BleepingComputer
Jan 09, 2018
Signal Intelligence
Confidence
95%
EPSS
93.89%
CVSS v3.1
7.8
Mentions
3
Last Seen
Sep 04, 2023
CNA Information
Analyst Note
Auto-imported from Google Project Zero — confirmed zero-day by definition.
Threat Actors 31
Lazarus Group
apt_group
Information theft and espionage
🇰🇵 KP
Cobalt
apt_group
Financial crime
🇷🇺 RU
GOLD SOUTHFIELD
apt_group
Financial gain
🇷🇺 RU
Harvester
apt_group
Information theft and espionage
Unknown
Careto
apt_group
Information theft and espionage
🇪🇸 ES
Leviathan
apt_group
Information theft and espionage
🇨🇳 CN
Hacking Team
apt_group
🇮🇹 IT
FusionCore
apt_group
🇪🇺 EU
DNSpionage
apt_group
Information theft and espionage
🇮🇷 IR
HAZY TIGER
apt_group
Information theft and espionage
🇮🇳 IN
Equation Group
apt_group
Sabotage and destruction
🇺🇸 US
Infy
apt_group
Information theft and espionage
🇮🇷 IR
Group 27
apt_group
Information theft and espionage
🇨🇳 CN
Gorilla
apt_group
null
Inception Framework
apt_group
Information theft and espionage
🇷🇺 RU
Lucky Cat
apt_group
Information theft and espionage
🇨🇳 CN
TA428
apt_group
Information theft and espionage
🇨🇳 CN
Pirate Panda
apt_group
Information theft and espionage
🇨🇳 CN
TA413
apt_group
Information theft and espionage
🇨🇳 CN
Inception
apt_group
Information theft and espionage
🇷🇺 RU
PhantomCore
apt_group
🇷🇺 RU
APT 22
apt_group
Information theft and espionage
🇨🇳 CN
Operation Cobalt Whisper
apt_group
Financial crime
🇨🇳 CN
Webworm
apt_group
Information theft and espionage
🇨🇳 CN
RedAlpha
apt_group
Information theft and espionage
🇨🇳 CN
APT 6
apt_group
Information theft and espionage
🇨🇳 CN
Tonto Team
apt_group
Information theft and espionage
🇨🇳 CN
RANCOR
apt_group
Information theft and espionage
🇨🇳 CN
Red October
apt_group
🇷🇺 RU
ToddyCat
apt_group
Information theft and espionage
🇨🇳 CN
Mana Team
apt_group
🇨🇳 CN
Triage Info
Decided atMar 05, 2026