PT-2017-4165 · Microsoft · Office 365+1
Published
2017-10-10
·
Updated
2025-01-23
·
CVE-2017-11774
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Microsoft Outlook versions 2010 SP2 through 2016
Microsoft Office 365 (affected versions not specified)
Description
The issue is related to the improper handling of objects in memory by Microsoft Outlook, allowing an attacker to execute arbitrary commands and bypass security features. This vulnerability has been exploited by Iranian hackers, according to the US Cyber Command. The vulnerability can be used to remotely execute code on a victim's device by substituting the home page of the Outlook client with a malicious HTML page. It is estimated that the vulnerability affects a significant number of devices worldwide, given the widespread use of Microsoft Outlook.
Recommendations
For Microsoft Outlook versions 2010 SP2 through 2016, update to a newer version that includes the fix for this vulnerability.
For Microsoft Office 365, at the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the vulnerable Outlook client to minimize the risk of exploitation. Avoid using the Outlook client until the issue is resolved.
Exploit
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Office 365
Outlook