EXPOSURES › CVE-2017-11774
CVE-2017-11774
HIGH ⌖ ON CISA KEV · EXPLOITEDA memory handling flaw in Microsoft Outlook allowed attackers to bypass security features and execute arbitrary commands.
This vulnerability in Microsoft Office Outlook stemmed from improper memory object handling, enabling attackers to bypass security controls and execute commands. For DIB organizations, this represents a critical RCE risk that could compromise sensitive data and violate CMMC/NIST 800-171 requirements if exploited. Organizations must ensure all Microsoft Office components are patched to the latest versions to mitigate this threat.
Shame score — A known memory handling flaw in a widely deployed productivity tool that allowed command execution, indicating a significant gap in Microsoft's security posture for a product used across the DIB.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Office Outlook contains a security feature bypass vulnerability due to improperly handling objects in memory. Successful exploitation allows an attacker to execute commands.
"Microsoft Office Outlook contains a security feature bypass vulnerability due to improperly handling objects in memory. Successful exploitation allows an attacker to execute commands."
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |