CISA Known Exploited Vulnerability

CVE-2017-11774

Microsoft · Office

Microsoft Office Outlook Security Feature Bypass Vulnerability

Date added
BOD 22-01 due date
CWE CWE-119
Ransomware Unknown

CISA description

Microsoft Office Outlook contains a security feature bypass vulnerability due to improperly handling objects in memory. Successful exploitation allows an attacker to execute commands.

Required action

Apply updates per vendor instructions.