Microsoft Office vulnerability
Microsoft Office memory corruption vulnerability enabling remote code execution with user privileges. Actively exploited in ransomware campaigns.
Today item, not a backlog item.
Critical remote code execution flaw in Office allowing attackers to execute arbitrary code through malformed documents. High real-world exploitation activity including ransomware deployment.
Is it exploitable?
— the evidence, ranked above the scoreWho’s exploiting it?
— attribution turns risk into urgencyNo confirmed (advisory-backed) threat-actor attribution is established for this record. Absence of a named actor is not absence of compromise — see Coverage & confidence.
These are not confirmed attribution and do not name this record’s headline actor. Each is tier-labeled and cited; an inferred link is a structural ATT&CK chain (a group uses a tool whose reference cites this CVE), never a statement that the source names the group.
Why it matters
— the attack path, told twice: adversary, then boardFront door — unauthenticated access narrative 1
Keys to the kingdom — privilege/identity takeover narrative 2
Lateral reach — past segmentation narrative 3
What to do
— defensible action- Remediate per the vendor advisory — confirm the fixed build for your version and verify exposure.1