CVE-2017-11774 Information
Feb 14, 2021
cve
Description
Microsoft Outlook 2010 SP2 Outlook 2013 SP1 and RT SP1 and Outlook 2016 allow an attacker to execute arbitrary commands due to how Microsoft Office handles objects in memory aka \Microsoft Outlook Security Feature Bypass Vulnerability.\
CVSS Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Reference
http://www.securityfocus.com/bid/101098 http://www.securitytracker.com/id/1039542 https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11774 https://sensepost.com/blog/2017/outlook-home-page-another-ruler-vector/
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
7.8
Share on: