SB2017072801 - Multiple vulnerabilities in Microsoft Office Outlook
Published: July 28, 2017
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 3 secuirty vulnerabilities.
1) Buffer overflow (CVE-ID: CVE-2017-8663)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to boundary error when parsing email messages. A remote unauthenticated attacker can create a specially crafted email message, send it to the victim and execute arbitrary code on the target system, when the malicious email is open by the victim.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
2) Information disclosure (CVE-ID: CVE-2017-8572)
The vulnerability allows a remote attacker to obtain potentially sensitive information.
The vulnerability exists due to boundary error when parsing documents in Microsoft Outlook. A remote attacker can create a specially crafted document, trick the victim into opening it and gain access to potentially sensitive information.
3) Improper input validation (CVE-ID: CVE-2017-8571)
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to an error when processing specially crafted document in Microsoft Office Outlook. A remote attacker can create a specially crafted document, trick the victim into opening it and interact with the document by clicking a specific cell.
Successful exploitation of the vulnerability may allow an attacker to bypass certain security restrictions.
Remediation
Install update from vendor's website.