High 7.8
KEV + Ransomware
CVE-2017-0199
CVE-2017-0199 Exploited in Phishing Campaign Delivering Remcos RAT via Microsoft Office
Vendor / product: Microsoft Office
Event date: 2024-09-11
Public PoC: Yes
First tracked by RiskWire: 2026-09-30
CISA KEV catalog
Added to KEV
Federal remediation due
2022-05-03 (1611 days overdue)
Ransomware campaign use
Known
CISA description
Microsoft Office and WordPad contain an unspecified vulnerability due to the way the applications parse specially crafted files. Successful exploitation allows for remote code execution.
Required action
Apply updates per vendor instructions.
Sources & citations (2)
- 프로젝트 자제 구매 요청서로 위장한 피싱 메일 주의 asec.ahnlab.com · 2026-09-29
- Beware of Phishing Emails That Disguise Themselves as Project Material Purchase Requests hendryadrian.com · 2026-09-29
References
See CVE-2017-0199 in context
RiskWire tracks every exploited CVE this week, cross-referenced against CISA KEV with federal remediation deadlines. Filtered to your vendor stack.
Book a 20-min demo →