ID:2171 - Exploit for Security restrictions bypass in Microsoft Outlook - CVE-2017-11774

 
Main Vulnerability Database Exploits ID:2171 - Exploit for Security restrictions bypass in Microsoft Outlook - CVE-2017-11774

ID:2171 - Exploit for Security restrictions bypass in Microsoft Outlook - CVE-2017-11774

Published: March 18, 2020


Vulnerability identifier: #VU8767
Vulnerability risk: Low
CVE-ID: CVE-2017-11774
CWE-ID: CWE-264
Exploitation vector: Remote access
Vulnerable software:
Microsoft Outlook

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to bypass security restrictions on the target system.

The vulnerability exists due to an error when Microsoft Office improperly handles objects in memory. A remote attacker can provide a specially crafted document file, trick the victim into opening it and execute arbitrary commands.


Remediation

Install updates from vendor's website.