Netskope Threat Labs

CVE-2017-0199

ATP Sandbox Adv. HeuristicsAVNetskope IPS

CVE-2017-0199 is a remote code execution vulnerability in Microsoft Office and Windows OLE that cyberattackers exploit via malicious documents to download and execute malware payloads. A crafted document could load an embedded object from a remote server and hand execution to the downloaded content, defeating the usual need for macros. Cyberattackers weaponized it within days of disclosure, and it became a fixture of targeted phishing campaigns that delivered commodity and nation state tooling.

First seen
January 2022
Last seen
October 2026
Alert Name
Binary.Exploit.CVE-2017-0199
Document-Excel.Exploit.CVE-2017-0199
Document-HTML.Exploit.CVE-2017-0199
Document-Office.Exploit.CVE-2017-0199
Document-OLE.Exploit.CVE-2017-0199
Document-PDF.Exploit.CVE-2017-0199
Document-PowerPoint.Exploit.CVE-2017-0199
Document-RTF.Exploit.CVE-2017-0199
Document-Word.Exploit.CVE-2017-0199
Document-Word.Trojan.CVE-2017-0199