CVE-2017-11774
KEVHIGH 7.8EPSS 59.9%
Microsoft Outlook 2010 SP2, Outlook 2013 SP1 and RT SP1, and Outlook 2016 allow an attacker to execute arbitrary commands, due to how Microsoft Office handles objects in memory, aka "Microsoft Outlook Security Feature Bypass Vulnerability."
- CVSS v3.1
- 7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - CVSS v3.1
- 7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - CVSS v2.0
- 6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P - EPSS
- 59.89% chance of exploitation in the next 30 days, 99th percentile
- CISA KEV
- added 2021-11-03
- Published
- 2017-10-13
- Updated
- 2025-10-21
Proof-of-concept exploits (1)
- devcoinfet/SniperRoost1★ · 2019-08-16