CVE-2017-8570
Prioritize patching. It under exploitation confirmed by CISA, has a public proof of concept and 2 threat group(s) use it.
Groups known to exploit this vulnerability (MITRE ATT&CK attribution).
Apply updates per vendor instructions.
Microsoft Office has a flaw in how it manages data in memory that allows attackers to run malicious code on your computer by sending you a specially crafted file. This is dangerous because it can give attackers complete control of your system.
A memory handling vulnerability in Microsoft Office enables remote code execution when processing specially crafted documents. The attack vector is user interaction (opening a malicious file), with no additional privileges required. Successful exploitation results in arbitrary code execution in the context of the affected Office application.