Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Office Memory Corruption Vulnerability".
https://blog.talosintelligence.com/2022/05/bitter-apt-adds-bangladesh-to-their.html
https://www.netskope.com/blog/new-formbook-campaign-delivered-through-phishing-emails
https://vb2020.vblocalhost.com/uploads/VB2020-06.pdf
https://securelist.com/cactuspete-apt-groups-updated-bisonal-backdoor/97962/
https://blog.talosintelligence.com/2020/03/bisonal-10-years-of-play.html
https://www.forcepoint.com/blog/x-labs/bitter-targeted-attack-against-pakistan
https://www.symantec.com/connect/blogs/tick-cyberespionage-group-zeros-japan
Published: 2018-01-10
Updated: 2025-03-26
Named Vulnerability: Equation EditorKnown Exploited Vulnerability (KEV)
Base Score: 9.3
Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C
Severity: High
Base Score: 8.8
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity: High
EPSS: 0.9418