SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2017-11774

Microsoft Office Outlook Security Feature Bypass Vulnerability

KEVHIGH 7.8EPSS 59.9%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 3 May 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

Microsoft Outlook 2010 SP2, Outlook 2013 SP1 and RT SP1, and Outlook 2016 allow an attacker to execute arbitrary commands, due to how Microsoft Office handles objects in memory, aka "Microsoft Outlook Security Feature Bypass Vulnerability."

CVSS 3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
59.89% probability · 99th percentile
CISA KEV
Listed 3 November 2021 · due 3 May 2022
Weakness
CWE-119
Affected
microsoft/outlook
Source
secure@microsoft.com

CISA notes

Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2017-11774

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.