First published: Fri Oct 13 2017(Updated: )
Microsoft Outlook 2010 SP2, Outlook 2013 SP1 and RT SP1, and Outlook 2016 allow an attacker to execute arbitrary commands, due to how Microsoft Office handles objects in memory, aka "Microsoft Outlook Security Feature Bypass Vulnerability."
Credit: secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Outlook | =sp1 | |
Microsoft Outlook | =2010-sp2 | |
Microsoft Outlook | =2013-sp1 | |
Microsoft Outlook | =2016 | |
Microsoft Outlook | =2013-sp1 | |
Microsoft Outlook | =2013-sp1 | |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-11774 has been rated as important severity due to its potential to allow arbitrary command execution.
To fix CVE-2017-11774, users should apply the latest security updates provided by Microsoft for their respective Outlook versions.
CVE-2017-11774 affects Microsoft Outlook 2010 SP2, Outlook 2013 SP1, Outlook 2016, and certain releases of Outlook for RT.
Yes, CVE-2017-11774 can be exploited remotely by an attacker to execute arbitrary commands.
Yes, CVE-2017-11774 is a known vulnerability and has been documented in various security advisories.