Security Updates for Outlook (September 2017)

high Nessus Plugin ID 103456

Synopsis

The version of Outlook installed on the remote host is affected by multiple vulnerabilities.

Description

The version of Microsoft Outlook installed on the remote host is missing security updates. It is, therefore, affected by multiple vulnerabilities :

- A remote code execution vulnerability exists in the way that Microsoft Outlook parses specially crafted email messages. An attacker who successfully exploited the vulnerability could take control of an affected system to then install programs; view, change, or delete data; or create new accounts with full user rights. (CVE-2017-0106)

- A security feature bypass vulnerability exists in Microsoft Office software when it improperly handles the parsing of file formats. To exploit the vulnerability, an attacker would have to convince a user to open a specially crafted file. (CVE-2017-0204)

- A remote code execution vulnerability exists when Microsoft Office improperly validates input before loading dynamic link library (DLL) files. An attacker who successfully exploited this vulnerability could take control of an affected system to then install programs;
view, change, or delete data; or create new accounts with full user rights. (CVE-2017-8506)

- A remote code execution vulnerability exists in the way that Microsoft Outlook parses specially crafted email messages. An attacker who successfully exploited this vulnerability could take control of an affected system.
(CVE-2017-8507)

- A security feature bypass vulnerability exists in Microsoft Office software when it improperly handles the parsing of file formats. (CVE-2017-8508)

- A security feature bypass vulnerability exists when Microsoft Office Outlook improperly handles input.
An attacker who successfully exploited the vulnerability could execute arbitrary commands. (CVE-2017-8571)

- An information disclosure vulnerability exists when Microsoft Outlook fails to properly validate authentication requests. (CVE-2017-8572)

- A remote code execution vulnerability exists in the way that Microsoft Outlook parses specially crafted email messages. An attacker who successfully exploited the vulnerability could take control of an affected system.
(CVE-2017-8663)

Solution

Microsoft has released a set of patches for Outlook 2007, 2010, 2013, and 2016.

See Also

http://www.nessus.org/u?8ac9b313

http://www.nessus.org/u?8f4ab525

http://www.nessus.org/u?16a66c3d

http://www.nessus.org/u?e5d09682

http://www.nessus.org/u?92c027cb

Plugin Details

Severity: High

ID: 103456

File Name: smb_nt_ms17_sep_outlook.nasl

Version: 1.8

Type: local

Agent: windows

Published: 9/25/2017

Updated: 11/12/2019

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: High

Base Score: 9.3

Temporal Score: 6.9

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2017-8663

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:microsoft:office, cpe:/a:microsoft:outlook

Required KB Items: SMB/MS_Bulletin_Checks/Possible

Exploit Ease: No known exploits are available

Patch Publication Date: 9/12/2017

Vulnerability Publication Date: 9/12/2017

Reference Information

CVE: CVE-2017-0106, CVE-2017-0204, CVE-2017-8506, CVE-2017-8507, CVE-2017-8508, CVE-2017-8571, CVE-2017-8572, CVE-2017-8663

BID: 97413, 97458, 98811, 98827, 98828, 99452, 99453, 100004

MSFT: MS17-4011089, MS17-4011090, MS17-4011091, MS17-4011110

MSKB: 4011089, 4011090, 4011091, 4011110