Skip to main content
Mallory
HighCISA KEVExploited in the wildPublic exploit

Microsoft Office Equation Editor Memory Corruption RCE

IdentifiersCVE-2018-0798CWE-119

CVE-2018-0798 is a remote code execution vulnerability in Microsoft Office Equation Editor affecting Microsoft Office 2007, 2010, 2013, and 2016. The issue is described by Microsoft as a memory corruption vulnerability caused by the way Equation Editor handles objects in memory. In observed exploitation, attackers embedded malicious OLE content in weaponized Office documents, including RTF and Excel files, which triggered Equation Editor when the document was opened. Successful exploitation allowed attacker-supplied shellcode or follow-on payloads to be executed on the victim system.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation can result in arbitrary code execution in the context of the user who opens the malicious Office document. In real-world campaigns, this has been used for initial compromise, downloader execution, malware installation, persistence staging, and delivery of espionage tooling. If the victim has elevated privileges, the attacker may gain broader control of the affected host.

Mitigation

If you can’t patch tonight, do this now.

Until patching is complete, reduce exposure by blocking or sandboxing untrusted Office attachments, especially RTF and legacy OLE-bearing documents; disable or restrict opening of documents from email and the internet using Protected View and attachment filtering; and monitor for Equation Editor child-process activity and suspicious follow-on execution from Office applications. Restrict user privileges to limit post-exploitation impact.

Remediation

Patch, then assume compromise.

Apply Microsoft's security updates for CVE-2018-0798 to affected Microsoft Office installations, including supported Office 2007, 2010, 2013, and 2016 versions. Ensure Equation Editor-related fixes are fully deployed across endpoints and remove or upgrade unsupported Office versions where patching is not available. Validate patch coverage on systems that process email attachments or untrusted Office documents.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
Microsoft CorporationOfficeapplication
Microsoft CorporationOffice Compatibility Packapplication
Microsoft CorporationWordapplication

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence14

Every observed campaign linking this CVE to a named adversary.

Associated malware5

Malware families riding this exploit, with evidence and IOCs.

Detection signatures1

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity2

Community discussion across Reddit, Mastodon, and other social sources.