PT-2017-4165 · Microsoft · Office 365+1

Published

2017-10-10

·

Updated

2025-01-23

·

CVE-2017-11774

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft Outlook versions 2010 SP2 through 2016 Microsoft Office 365 (affected versions not specified)
Description The issue is related to the improper handling of objects in memory by Microsoft Outlook, allowing an attacker to execute arbitrary commands and bypass security features. This vulnerability has been exploited by Iranian hackers, according to the US Cyber Command. The vulnerability can be used to remotely execute code on a victim's device by substituting the home page of the Outlook client with a malicious HTML page. It is estimated that the vulnerability affects a significant number of devices worldwide, given the widespread use of Microsoft Outlook.
Recommendations For Microsoft Outlook versions 2010 SP2 through 2016, update to a newer version that includes the fix for this vulnerability. For Microsoft Office 365, at the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the vulnerable Outlook client to minimize the risk of exploitation. Avoid using the Outlook client until the issue is resolved.

Exploit

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-05769
CVE-2017-11774

Affected Products

Office 365
Outlook