← Vulnerability feed

Vulnerability record · CVE-2017-11774 · published 13 October 2017

CVE-2017-11774: Microsoft Outlook memory handling flaw allows arbitrary command execution

Microsoft · Outlook

Microsoft Outlook 2010 SP2, 2013 SP1/RT SP1 and 2016 mishandle objects in memory, letting an attacker bypass Outlook security features and execute arbitrary commands. It matters because Outlook is widely deployed and the flaw is listed in CISA KEV, so it has been exploited in the wild.

7.8 CVSS 3.1 High CISA KEV since 3 Nov 2021 EPSS 60% · top 0.9% CWE-119 · Memory buffer overflow
7.8CVSS 3.1 base score, v2 6.8
60%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
9References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Microsoft Outlook 2010 SP2, Outlook 2013 SP1 and RT SP1, and Outlook 2016 allow an attacker to execute arbitrary commands, due to how Microsoft Office handles objects in memory, aka "Microsoft Outlook Security Feature Bypass Vulnerability."

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

high priorityIt is a KEV-listed, actively exploited Outlook flaw with high EPSS, though exploitation requires local user interaction.

What it is

Microsoft Outlook 2010 SP2, 2013 SP1/RT SP1 and 2016 mishandle objects in memory, letting an attacker bypass Outlook security features and execute arbitrary commands. It matters because Outlook is widely deployed and the flaw is listed in CISA KEV, so it has been exploited in the wild.

Impact

An attacker who gets code to run in the context of the victim can execute arbitrary commands on the host, giving full compromise of confidentiality, integrity and availability of the user's data and session.

Attack surface

The CVSS vector is local with user interaction required (AV:L/UI:R/PR:N), meaning the victim must open or interact with a crafted Outlook item or document; no prior authentication is needed.

Exploitation

CVE-2017-11774 is in CISA KEV (added 2021-11-03) and has an EPSS 30-day probability of about 0.60 (99th percentile), and a public exploit write-up is referenced, indicating active exploitation.

What to do

  • Apply the Microsoft security update for Outlook referenced in the MSRC advisory CVE-2017-11774.
  • Upgrade or retire unsupported Outlook 2010/2013/2016 builds where patching is no longer possible.
  • Disable or restrict Outlook Home Page and related legacy folder/webview features via policy where feasible.
  • Block or warn on untrusted Outlook items and attachments at the mail gateway and endpoint.
  • Limit user privileges so command execution from Outlook does not yield administrative rights.

Detection

  • Monitor for Outlook spawning child processes such as cmd.exe, powershell.exe or wscript.exe.
  • Alert on creation or modification of Outlook Home Page / folder webview registry or profile settings.
  • Hunt for suspicious Outlook item files or attachments that trigger script or command execution.
  • Review endpoint telemetry for command execution originating from outlook.exe outside normal behavior.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2017-11774 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Microsoft Office Outlook Security Feature Bypass Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-11774 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-23397Microsoft Outlook improper input validation privilege escalationCVE-2023-23397 is a critical elevation of privilege flaw in Microsoft Outlook caused by improper input validation and an authentication bypass by cap…KEVEPSS 97%analysed8.8CVE-2023-35311Microsoft Outlook security feature bypass via TOCTOU race conditionCVE-2023-35311 is a security feature bypass in Microsoft Outlook caused by a time-of-check time-of-use (TOCTOU) race condition (CWE-367). It affects …KEVEPSS 16%analysed8.8CVE-2007-0671Microsoft Excel remote code execution via malformed fileCVE-2007-0671 is an unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, that allows re…KEVEPSS 43%analysed7.8CVE-2015-1641Microsoft Office Word RTF out-of-bounds write memory corruptionMicrosoft Word and related Office components (Word 2007/2010/2013, Word for Mac 2011, Office Compatibility Pack, Word Automation Services, Office Web…KEVEPSS 97%analysed10.0CVE-2001-0538Microsoft Outlook View ActiveX Control allows remote command executionThe Outlook View ActiveX Control in Microsoft Outlook 2002 and earlier fails to properly restrict how it is invoked, so a malicious HTML e-mail or we…EPSS 53%analysed9.3CVE-2013-3870Microsoft outlook vulnerabilityDouble free vulnerability in Microsoft Outlook 2007 SP3 and 2010 SP1 and SP2 allows remote attackers to execute arbitrary code by including many nest…EPSS 19%9.3CVE-2010-2728Microsoft outlook memory buffer overflow vulnerabilityHeap-based buffer overflow in Microsoft Outlook 2002 SP3, 2003 SP3, and 2007 SP2, when Online Mode for an Exchange Server is enabled, allows remote a…EPSS 17%9.3CVE-2010-0266Microsoft Outlook SMB attachment code execution flawMicrosoft Outlook 2002 SP3, 2003 SP3, and 2007 SP1/SP2 fail to properly verify e-mail attachments whose PR_ATTACH_METHOD property is set to ATTACH_BY…EPSS 55%analysed

Source: NIST National Vulnerability Database (record CVE-2017-11774), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.