Vulnerability record · CVE-2017-11774 · published 13 October 2017
CVE-2017-11774: Microsoft Outlook memory handling flaw allows arbitrary command execution
Microsoft · Outlook
Microsoft Outlook 2010 SP2, 2013 SP1/RT SP1 and 2016 mishandle objects in memory, letting an attacker bypass Outlook security features and execute arbitrary commands. It matters because Outlook is widely deployed and the flaw is listed in CISA KEV, so it has been exploited in the wild.
Description
Microsoft Outlook 2010 SP2, Outlook 2013 SP1 and RT SP1, and Outlook 2016 allow an attacker to execute arbitrary commands, due to how Microsoft Office handles objects in memory, aka "Microsoft Outlook Security Feature Bypass Vulnerability."
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityIt is a KEV-listed, actively exploited Outlook flaw with high EPSS, though exploitation requires local user interaction.
What it is
Microsoft Outlook 2010 SP2, 2013 SP1/RT SP1 and 2016 mishandle objects in memory, letting an attacker bypass Outlook security features and execute arbitrary commands. It matters because Outlook is widely deployed and the flaw is listed in CISA KEV, so it has been exploited in the wild.
Impact
An attacker who gets code to run in the context of the victim can execute arbitrary commands on the host, giving full compromise of confidentiality, integrity and availability of the user's data and session.
Attack surface
The CVSS vector is local with user interaction required (AV:L/UI:R/PR:N), meaning the victim must open or interact with a crafted Outlook item or document; no prior authentication is needed.
Exploitation
CVE-2017-11774 is in CISA KEV (added 2021-11-03) and has an EPSS 30-day probability of about 0.60 (99th percentile), and a public exploit write-up is referenced, indicating active exploitation.
What to do
- Apply the Microsoft security update for Outlook referenced in the MSRC advisory CVE-2017-11774.
- Upgrade or retire unsupported Outlook 2010/2013/2016 builds where patching is no longer possible.
- Disable or restrict Outlook Home Page and related legacy folder/webview features via policy where feasible.
- Block or warn on untrusted Outlook items and attachments at the mail gateway and endpoint.
- Limit user privileges so command execution from Outlook does not yield administrative rights.
Detection
- Monitor for Outlook spawning child processes such as cmd.exe, powershell.exe or wscript.exe.
- Alert on creation or modification of Outlook Home Page / folder webview registry or profile settings.
- Hunt for suspicious Outlook item files or attachments that trigger script or command execution.
- Review endpoint telemetry for command execution originating from outlook.exe outside normal behavior.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2017-11774 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Microsoft Office Outlook Security Feature Bypass Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/101098 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039542 | Broken LinkThird Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11774 | PatchVendor Advisory |
| https://sensepost.com/blog/2017/outlook-home-page-another-ruler-vector/ | Exploit |
| http://www.securityfocus.com/bid/101098 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039542 | Broken LinkThird Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11774 | PatchVendor Advisory |
| https://sensepost.com/blog/2017/outlook-home-page-another-ruler-vector/ | Exploit |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-11774 | US Government Resource |
Track CVE-2017-11774 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-11774), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.