Microsoft Office Outlook CVE-2017-11774 Security Bypass Vulnerability
BID:101098
Info
Microsoft Office Outlook CVE-2017-11774 Security Bypass Vulnerability
| Bugtraq ID: | 101098 |
| Class: | Input Validation Error |
| CVE: |
CVE-2017-11774 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 10 2017 12:00AM |
| Updated: | Oct 10 2017 12:00AM |
| Credit: | Etienne Stalmans of SensePost |
| Vulnerable: |
Microsoft Outlook 2016 (64-bit editions) Microsoft Outlook 2016 (32-bit editions) Microsoft Outlook 2013 Service Pack 1 (64-bit editions) 0 Microsoft Outlook 2013 Service Pack 1 (32-bit editions) 0 Microsoft Outlook 2013 RT Service Pack 1 Microsoft Outlook 2010 (64-bit editions) Service Pack 2 Microsoft Outlook 2010 (32-bit editions) Service Pack 2 |
| Not Vulnerable: | |
Discussion
Microsoft Office Outlook CVE-2017-11774 Security Bypass Vulnerability
Microsoft Office Outlook is prone to a security-bypass vulnerability because it fails to properly handle input.
An attacker can leverage this issue to bypass certain security restrictions and execute arbitrary commands in the context of the affected application; this may aid in launching further attacks.
Microsoft Office Outlook is prone to a security-bypass vulnerability because it fails to properly handle input.
An attacker can leverage this issue to bypass certain security restrictions and execute arbitrary commands in the context of the affected application; this may aid in launching further attacks.
Exploit / POC
Microsoft Office Outlook CVE-2017-11774 Security Bypass Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Microsoft Office Outlook CVE-2017-11774 Security Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.