Lucene search

K
cveMicrosoftCVE-2017-11774
HistoryOct 13, 2017 - 1:29 p.m.

CVE-2017-11774

2017-10-1313:29:00
CWE-119
microsoft
web.nvd.nist.gov
969
In Wild
microsoft
outlook
security
bypass
vulnerability
nvd
cve-2017-11774

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

7.7

Confidence

High

EPSS

0.886

Percentile

98.8%

Microsoft Outlook 2010 SP2, Outlook 2013 SP1 and RT SP1, and Outlook 2016 allow an attacker to execute arbitrary commands, due to how Microsoft Office handles objects in memory, aka “Microsoft Outlook Security Feature Bypass Vulnerability.”

Affected configurations

Nvd
Vulners
Node
microsoftoutlookMatch2010sp2
OR
microsoftoutlookMatch2013sp1-
OR
microsoftoutlookMatch2013sp1rt
OR
microsoftoutlookMatch2016
VendorProductVersionCPE
microsoftoutlook2010cpe:2.3:a:microsoft:outlook:2010:sp2:*:*:*:*:*:*
microsoftoutlook2013cpe:2.3:a:microsoft:outlook:2013:sp1:*:*:-:*:*:*
microsoftoutlook2013cpe:2.3:a:microsoft:outlook:2013:sp1:*:*:rt:*:*:*
microsoftoutlook2016cpe:2.3:a:microsoft:outlook:2016:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Microsoft Outlook",
    "vendor": "Microsoft Corporation",
    "versions": [
      {
        "status": "affected",
        "version": "Microsoft Outlook 2010 SP2"
      },
      {
        "status": "affected",
        "version": "Outlook 2013 SP1 and RT SP1"
      },
      {
        "status": "affected",
        "version": "Outlook 2016"
      }
    ]
  }
]

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

7.7

Confidence

High

EPSS

0.886

Percentile

98.8%