CVE-2017-11774
גבוהה 7.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Microsoft Office Outlook Security Feature Bypass Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
Microsoft Outlook 2010 SP2, Outlook 2013 SP1 and RT SP1, and Outlook 2016 allow an attacker to execute arbitrary commands, due to how Microsoft Office handles objects in memory, aka "Microsoft Outlook Security Feature Bypass Vulnerability."
מדדים
- CVSS 3.1
-
7.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 60% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-119
מוצרים מושפעים
microsoft: outlook
קישורים
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11… PatchVendor Advisory
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11… PatchVendor Advisory
- https://sensepost.com/blog/2017/outlook-home-page-another-ruler-vector/ Exploit
- https://sensepost.com/blog/2017/outlook-home-page-another-ruler-vector/ Exploit
- http://www.securityfocus.com/bid/101098 Broken LinkThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1039542 Broken LinkThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/101098 Broken LinkThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1039542 Broken LinkThird Party AdvisoryVDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-201… US Government Resource