# Anvilogic 8.0 is generally available

[Learn more](/content/learn/anvilogic-8-0-automate-the-soc/index.html)

\
[MyMeta Logo](/content/site-root.html)

On-Demand Webinar

# Abuse EQNEDT32.EXE CVE-2017-11882

## Threats + Use Case

May 5, 2021 12:00 AM CST

Online

### Overview of CVE-2017-11882

CVE-2017-11882 affects several versions of Microsoft Office and, when exploited, allows a remote user to run arbitrary code in the context of the current user as a result of improperly handling objects in memory. The vulnerability exists in the old Equation Editor (EQNEDT32.EXE), a component of Microsoft Office that is used to insert and evaluate mathematical formulas. As the EQNEDT32.exe is compiled using an older compiler and does not support address space layout randomization (ASLR), a technique that guards against the exploitation of memory-corruption vulnerabilities, the attacker can easily alter the flow of program execution. This use case is geared towards detecting the potential malicious Microsoft Office payload (CVE-2017-11882) on host.

### References

- [https://www.fireeye.com/blog/threat-research/2017/12/targeted-attack-in-middle-east-by-apt34.html](https://www.fireeye.com/blog/threat-research/2017/12/targeted-attack-in-middle-east-by-apt34.html)

### Tags

- Execution
- APT32
- APT41
- Splunk
- Cobalt Group
- Frankenstein
- Inception
- Leviathan
- Patchwork
- Tropic Trooper
- Exploitation for Client Execution

## Get the Latest Resources

Demo Series

[Watch](https://www.youtube.com/watch?v=Fo8F8-G3OEo)

Demo Series

[Watch](https://www.youtube.com/watch?v=pBuSjJIF3ac)

### Product Vision

May 5, 2021

4 min read

### Abuse EQNEDT32.EXE CVE-2017-11882

This is some text inside of a div block.

CVE-2017-11882 affects several versions of Microsoft Office...

## Resources

No items found.
