CVE-2017-11774
high · 7.8Actively exploitedOn the CISA Known Exploited Vulnerabilities catalog
Apply updates per vendor instructions.
Added 2021-11-03Remediation due 2022-05-03
Microsoft Outlook 2010 SP2, Outlook 2013 SP1 and RT SP1, and Outlook 2016 allow an attacker to execute arbitrary commands, due to how Microsoft Office handles objects in memory, aka "Microsoft Outlook Security Feature Bypass Vulnerability."
7.8
CVSS
59.6%
EPSS (exploit prob.)
99th
EPSS percentile
2017-10-13
Published
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weaknesses
CWE-119
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | outlook | 2010 |
| microsoft | outlook | 2013 |
| microsoft | outlook | 2013 |
| microsoft | outlook | 2016 |
Check a specific version with /api/v1/cve/match.
References
- http://www.securityfocus.com/bid/101098
- http://www.securitytracker.com/id/1039542
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11774
- https://sensepost.com/blog/2017/outlook-home-page-another-ruler-vector/
- http://www.securityfocus.com/bid/101098
- http://www.securitytracker.com/id/1039542
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11774
- https://sensepost.com/blog/2017/outlook-home-page-another-ruler-vector/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-11774
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2017-11774