Aller au contenu
Appaloosa Scout
HIGH 7.8 KEV

CVE-2017-11774

Microsoft Outlook 2010 SP2, Outlook 2013 SP1 and RT SP1, and Outlook 2016 allow an attacker to execute arbitrary commands, due to how Microsoft Office handles objects in memory, aka "Microsoft Outlook Security Feature Bypass Vulnerability."

CVSS v3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA Known Exploited Vulnerability

Ajouté au KEV
2021-11-03
Deadline remédiation
2022-05-03
Action requise
Apply updates per vendor instructions.
Ransomware
Non

Apps mobiles affectées

Configurations CPE vulnérables

Vendor Produit Plateforme Versions CPE 2.3 URI
microsoft outlook Android cpe:2.3:a:microsoft:outlook:2010:sp2:*:*:*:*:*:*
microsoft outlook iOS cpe:2.3:a:microsoft:outlook:2010:sp2:*:*:*:*:*:*
microsoft outlook Android cpe:2.3:a:microsoft:outlook:2013:sp1:*:*:-:*:*:*
microsoft outlook iOS cpe:2.3:a:microsoft:outlook:2013:sp1:*:*:-:*:*:*
microsoft outlook Android cpe:2.3:a:microsoft:outlook:2013:sp1:*:*:rt:*:*:*
microsoft outlook iOS cpe:2.3:a:microsoft:outlook:2013:sp1:*:*:rt:*:*:*
microsoft outlook Android cpe:2.3:a:microsoft:outlook:2016:*:*:*:*:*:*:*
microsoft outlook iOS cpe:2.3:a:microsoft:outlook:2016:*:*:*:*:*:*:*
Voir sur NVD ↗ Catalogue CISA KEV ↗