← Back to CVE List
Vulnerability Intelligence Report
Microsoft Office Outlook Security Feature Bypass Vulnerability

CVE-2017-11774

Microsoft Outlook 2010 SP2, Outlook 2013 SP1 and RT SP1, and Outlook 2016 allow an attacker to execute arbitrary commands, due to how Microsoft Office handles objects in memory, aka "Microsoft Outlook Security Feature Bypass Vulnerability."

CISA KEV SSVC: Active Exploitation
CVSS Base Score
7.8
HIGH
Exploitability:1.9
Impact Score:5.9
EPSS Probability:59.89%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-119 ↗CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

Affected Products & Versions

Vendor Product Affected Versions
Microsoft Corporation Microsoft Outlook Microsoft Outlook 2010 SP2 (affected), Outlook 2013 SP1 and RT SP1 (affected), Outlook 2016 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
59.893%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMicrosoft Corporation · Vendor · USA
Reserved2017-07-31T00:00:00
Published2017-10-13T13:00:00
Patch Date2017-10-10
Last Updated2025-10-21T23:55:31

LINK COPIED TO CLIPBOARD