ESET’s H1 2026 telemetry says exploitation attempts against CVE-2017-0199, a Microsoft Office and WordPad remote-code-execution vulnerability first disclosed in April 2017, more than doubled in Kenya between the second half of 2025 and the first half of 2026. For Windows administrators, the practical conclusion is blunt: an old malicious-document route that should have been closed through patching, software retirement and mail controls is still reaching users.

ESET’s Kenya-specific release, also carried by Africa Business Communities, frames the increase alongside rising QR-code phishing and Aotera malware detections. The company’s numbers are telemetry, not a census of every Kenyan network, and it acknowledges that its quishing comparison uses an incomplete baseline. But the CVE-2017-0199 finding deserves attention beyond ESET’s own reporting: the U.S. National Vulnerability Database still lists the flaw in CISA’s Known Exploited Vulnerabilities catalog, where the prescribed remediation remains to apply Microsoft’s updates.

This is not a story about a newly discovered Office zero-day. It is a warning that organizations with old Office installations, long-lived Windows endpoints, ungoverned email attachments and internet-facing Remote Desktop can convert routine phishing into a serious incident.

Cybersecurity analyst monitors a dashboard showing CVE exploitation, phishing alerts, exposed remote desktops, and suspicious login threats.CVE-2017-0199 remains a useful attack path​

CVE-2017-0199 affects legacy Microsoft Office and Windows components that can execute arbitrary code after a user opens a crafted document. The Microsoft-supplied vulnerability record cited by NVD names Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2016, Windows Vista SP2, Windows 7 SP1, Windows 8.1, Windows Server 2008 SP2 and Windows Server 2012 among affected software.

The important operational point is that “Office 2016” or “Windows 7” in an asset inventory is not merely a licensing or compatibility question. It can identify a device that needs immediate verification: which update channel it receives, whether it has the relevant security update, whether it is still supported, and whether users can open external documents on it. A machine that is technically reachable but absent from normal patch compliance reports is exactly the kind of exception that turns a nine-year-old vulnerability into current attacker value.

NVD assigns CVE-2017-0199 a high CVSS 3.1 score of 7.8 and records user interaction as required. That user-action condition should not be mistaken for a meaningful safeguard. The attack model fits ordinary business workflows: an invoice, shipping notice, contract, payroll document or document-sharing prompt persuades a recipient to open a file. ESET’s Kenyan report says scripts made up 46.2% of malicious email attachments in its reporting period, followed by Office documents at 14.4%, PDFs at 11.9% and archives at 9.7%.

This is why attachment policy matters as much as patch status. A vulnerable document handler is dangerous, but an organization that lets unsolicited external documents arrive directly in users’ inboxes, then gives users weak visual cues about origin and risk, supplies the social-engineering half of the attack.

The report points to legacy inventory failures, not a lack of advanced tools​

ESET’s most valuable Kenyan finding is not the percentage increase by itself. It is the combination of an old Office flaw, externally exposed Remote Desktop endpoints, default credentials or ports, and an email-driven delivery model. That combination describes gaps in asset control and baseline enforcement.

A security team cannot remediate a device it does not know exists. Administrators should begin by reconciling endpoint-management, identity, network-discovery and vulnerability-scanning records, then isolate the systems that fall into one of three categories: unsupported Windows or Office software, devices missing a current patch-management record, and systems that accept inbound remote access from the public internet.

The remediation sequence should be practical rather than ceremonial:

  • Inventory Office, Windows and Windows Server versions, including unmanaged laptops, shared PCs, jump hosts, virtual machines and appliances that embed Windows components.
  • Verify that every affected legacy build either has the applicable Microsoft security update or has been removed from normal document-opening duties pending replacement.
  • Block or tightly restrict external RDP exposure, require multifactor authentication for remote access, and remove default or shared administrative credentials.
  • Apply attachment filtering and sandboxing for scripts, Office documents, archives and PDFs, rather than treating file extensions as reliable indicators of risk.
  • Make the exception list visible to leadership, with a named owner and retirement date for every system that cannot be brought to the standard.

ESET’s Allan Juma told the company’s Kenya release that organizations should patch endpoints, apply a minimum protection standard and stop using default ports and passwords. That advice is basic because the observed failures are basic. A new endpoint product does not compensate for an unsupported workstation that can still open a hostile document, authenticate with a reused password and reach an unsegmented business network.

QR-code phishing shifts the risk to phones​

ESET says QR codes appeared in roughly 11% of phishing email detections globally during H1 2026, with Kenya seeing a 145% increase between H2 2025 and H1 2026. The company cautions that the Kenyan percentage rests on an incomplete baseline, so it should be treated as evidence of a rising direction rather than a precise measure of countrywide growth.

The technique, widely called quishing, matters to Windows and Microsoft 365 administrators because it can move a user out of the managed browser and protected endpoint environment. A phishing email received in Outlook on a corporate PC may contain only an image. The employee scans it with a personal iPhone or Android device, opens the destination away from corporate web filtering, then enters Microsoft 365 credentials or approves an MFA request.

That bypasses one of the assumptions behind desktop-centric email security: that the click happens where the security stack can inspect and control it. It may not. Security teams should make QR-code extraction and URL inspection a standard part of inbound email scanning, but they also need controls that survive the handoff to a mobile device.

For Microsoft 365 tenants, that means enforcing phishing-resistant MFA where feasible, restricting legacy authentication, reviewing conditional-access rules for unmanaged devices, and using sign-in logs to spot impossible travel, unfamiliar device registration and unusual token activity. Training should tell users to treat a QR code in an unsolicited email as a link whose destination is hidden—not as a neutral image.

ESET’s global H1 2026 threat report says its telemetry saw about 100,000 QR-code phishing detections per month, peaking in April. The Kenyan release’s comparison with North America is less useful than the underlying behavior: if users can authenticate from unmanaged devices, attackers do not need a sophisticated exploit to get around desktop defenses.

Aotera makes the initial compromise more valuable​

ESET also reports that Aotera, described as an infostealer and dropper, rose to fourth among detected malware families in Kenya. The company says it can deliver AgentTesla, Formbook, PureLogs, PhantomStealer and Vidar—families associated with credential theft and further compromise.

A dropper changes the incident-response calculation. The visible malware detection may be only the delivery mechanism, while credentials, browser data, remote-access tools or additional payloads may already have been deployed. A team that simply deletes the file and closes the ticket risks leaving a compromised account, scheduled task, startup entry, mailbox rule or stolen session token in place.

When Aotera or any comparable loader is found, responders should preserve evidence before reimaging, identify the initial delivery route, reset exposed credentials, revoke active sessions where the identity provider supports it, and hunt for the same attachment hash, sender infrastructure, URL and command-line behavior across the estate. The process should include cloud identities, not only the Windows device where the alert first appeared.

ESET’s report also says some Kenyan organizations have paid over what they believed were ransomware incidents that were not genuine ransomware. That is a separate but related failure of verification. A ransom note, locked account or inaccessible shared folder is not proof that files have been encrypted or stolen by a ransomware operator. Incident teams need to establish what has happened—encryption, exfiltration, credential theft, fraud, data destruction or a bluff—before authorizing payment, notifying customers or declaring a ransomware event.

The usable lesson is measurable hygiene​

The report’s Kenya figures cannot establish how many organizations are unpatched or how many exposed RDP systems remain online; ESET does not publish those raw population counts in its release. Nor does the company identify the sectors or organizations behind the detections. Those omissions limit any claim about national prevalence.

They do not weaken the immediate administrative lesson. CVE-2017-0199 is a known exploited Microsoft vulnerability with published patches, and ESET is seeing its exploitation attempts rise locally. Every organization should be able to answer, now, which endpoints still run the affected Office or Windows generations, which can open externally sourced documents, and which identities could be captured through a QR-driven Microsoft 365 phishing page.

If it cannot produce those answers, it has found the security gap ESET is describing.