Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE is unique from CVE-2018-0797 and CVE-2018-0812.
https://securelist.com/vulnerabilities-and-exploits-in-q2-2025/117333/
https://securelist.com/vulnerabilities-and-exploits-in-q1-2025/116624/
https://securelist.com/vulnerabilities-and-exploits-in-q4-2024/115761/
https://securelist.com/cloud-atlas-attacks-with-new-backdoor-vbcloud/115103/
https://securelist.com/exploits-and-vulnerabilities-q3-2024/114839/
https://securelist.com/vulnerability-exploit-report-q2-2024/113455/
https://www.tenable.com/cyber-exposure/tenable-2022-threat-landscape-report
https://blog.talosintelligence.com/2022/05/bitter-apt-adds-bangladesh-to-their.html
https://www.uptycs.com/blog/confucius-apt-deploys-warzone-rat
https://vb2020.vblocalhost.com/uploads/VB2020-06.pdf
https://securelist.com/cactuspete-apt-groups-updated-bisonal-backdoor/97962/
https://blog.talosintelligence.com/2020/03/bisonal-10-years-of-play.html
https://securelist.com/recent-cloud-atlas-activity/92016/
https://blog.trendmicro.com/trendlabs-security-intelligence/tropic-trooper-new-strategy/
https://www.trendmicro.com/en_us/research/18/b/deciphering-confucius-cyberespionage-operations.html
https://www.forcepoint.com/blog/x-labs/bitter-targeted-attack-against-pakistan
https://www.symantec.com/connect/blogs/tick-cyberespionage-group-zeros-japan
https://securelist.com/cloud-atlas-redoctober-apt-is-back-in-style/68083/
https://research.checkpoint.com/another-office-equation-rce-vulnerability/
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0802
https://github.com/rxwx/CVE-2018-0802
https://0patch.blogspot.com/2018/01/the-bug-that-killed-equation-editor-how.html