Skip to content
COOEY

EXPOSURES › CVE-2017-11774

CVE-2017-11774

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2017-11774 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 65/100 exploited-in-wildunpatchedrce

A memory handling flaw in Microsoft Outlook allowed attackers to bypass security features and execute arbitrary commands.

This vulnerability in Microsoft Office Outlook stemmed from improper memory object handling, enabling attackers to bypass security controls and execute commands. For DIB organizations, this represents a critical RCE risk that could compromise sensitive data and violate CMMC/NIST 800-171 requirements if exploited. Organizations must ensure all Microsoft Office components are patched to the latest versions to mitigate this threat.

Shame score — A known memory handling flaw in a widely deployed productivity tool that allowed command execution, indicating a significant gap in Microsoft's security posture for a product used across the DIB.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Microsoft Office Outlook contains a security feature bypass vulnerability due to improperly handling objects in memory. Successful exploitation allows an attacker to execute commands.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
Vulnerability in core Outlook component allowing command execution, though no public exploit or widespread breach reported in provided text.
cooey ↗ severe-fallout -0.60
Vulnerability in core Outlook component allowing command execution, though no public exploit or widespread breach reported in provided text.
"Microsoft Office Outlook contains a security feature bypass vulnerability due to improperly handling objects in memory. Successful exploitation allows an attacker to execute commands."
AFFECTED FEDRAMP PRODUCTS · 4
PRODUCTSTATUS
Azure Commercial Cloud
Microsoft
Authorized
Azure Government (includes Dynamics 365)
Microsoft
Authorized
Microsoft Office 365 GCC High
Microsoft
In Process
Office 365 Multi-Tenant & Supporting Services
Microsoft
Authorized