CVE-2017-11774

Description

Microsoft Outlook 2010 SP2, Outlook 2013 SP1 and RT SP1, and Outlook 2016 allow an attacker to execute arbitrary commands, due to how Microsoft Office handles objects in memory, aka Microsoft Outlook Security Feature Bypass Vulnerability.

Risk Information

Base Score
7.8
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
82.853

Associated Vulnerability

VulnerabilityOS Platform
Microsoft Outlook Security Feature Bypass Vulnerability for Microsoft Outlook 2013 (KB4011178) 32-Bit EditionWindows
Microsoft Outlook Security Feature Bypass Vulnerability for Microsoft Outlook 2013 (KB4011178) 64-Bit EditionWindows
Microsoft Outlook Security Feature Bypass Vulnerability for Microsoft Outlook 2016 (KB4011162) 32-Bit EditionWindows
Microsoft Outlook Security Feature Bypass Vulnerability for Microsoft Outlook 2016 (KB4011162) 64-Bit EditionWindows
Microsoft Outlook Security Feature Bypass Vulnerability for Microsoft Outlook 2010 (KB4011196) 64-Bit EditionWindows
Microsoft Outlook Security Feature Bypass Vulnerability for Microsoft Outlook 2010 (KB4011196) 32-Bit EditionWindows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-23335Security Update for Microsoft Outlook 2013 (KB4011178) 32-Bit Edition
PATCH-23336Security Update for Microsoft Outlook 2013 (KB4011178) 64-Bit Edition
PATCH-23294Security Update for Microsoft Outlook 2016 (KB4011162) 32-Bit Edition
PATCH-23295Security Update for Microsoft Outlook 2016 (KB4011162) 64-Bit Edition
PATCH-23370Security Update for Microsoft Outlook 2010 (KB4011196) 64-Bit Edition
PATCH-23371Security Update for Microsoft Outlook 2010 (KB4011196) 32-Bit Edition

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234