PT-2017-1869 · Microsoft · Office+1

Ryan Hanson

+1

·

Published

2017-04-11

·

Updated

2019-10-03

·

CVE-2017-0204

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Outlook versions 2007 SP3 through 2016
Description The issue is related to a security feature bypass in Microsoft Office software, specifically in Microsoft Outlook, where the software improperly handles the parsing of file formats. This can be exploited by a remote attacker using a specially crafted document to bypass the Office Protected View. The bypass by itself does not allow arbitrary code execution but can be used in conjunction with another vulnerability, such as a remote code execution vulnerability, to run arbitrary code. An attacker would have to convince a user to open a specially crafted file with an affected version of Microsoft Office software to exploit the vulnerability.
Recommendations For Microsoft Outlook versions 2007 SP3 through 2016, consider avoiding the use of Office software to open specially crafted files until a patch is available. As a temporary workaround, restrict access to the Office Protected View feature to minimize the risk of exploitation.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-01025
CVE-2017-0204

Affected Products

Office
Outlook