CVE-2017-8572High

Microsoft Outlook Information Disclosure Vulnerability

Published
July 27, 2017
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

An information disclosure vulnerability exists when Microsoft Outlook fails to properly validate authentication requests. To exploit the vulnerability an attacker would have to trick a user into browsing to a malicious website or to an SMB or UNC path destination. Alternatively the attacker could convince a user to load a malicious document that initiates an NTLM validation request without the consent of the user. An attacker who successfully tricked a user into disclosing the user's NTLM hash could attempt a brute-force attack to disclose the corresponding hash password. The security update addresses the vulnerability by correcting how Outlook validates authentication requests.

🎯 Affected products14

  • Microsoft Office 2010 Click-to-Run (C2R) for 32-bit editions
  • Microsoft Office 2010 Click-to-Run (C2R) for 64-bit editions
  • Microsoft Office 2013 Click-to-Run (C2R) for 32-bit editions
  • Microsoft Office 2013 Click-to-Run (C2R) for 64-bit editions
  • Microsoft Office 2016 Click-to-Run (C2R) for 32-bit editions
  • Microsoft Office 2016 Click-to-Run (C2R) for 64-bit editions
  • Microsoft Outlook 2007 Service Pack 3
  • Microsoft Outlook 2010 Service Pack 2 (32-bit editions)
  • Microsoft Outlook 2010 Service Pack 2 (64-bit editions)
  • Microsoft Outlook 2013 RT Service Pack 1
  • Microsoft Outlook 2013 Service Pack 1 (32-bit editions)
  • Microsoft Outlook 2013 Service Pack 1 (64-bit editions)
  • Microsoft Outlook 2016 (32-bit edition)
  • Microsoft Outlook 2016 (64-bit edition)

✅ Remediation

KB4011052 (Security Update) KB4011078 (Security Update) KB3213643 (Security Update) KB2956078 (Security Update) KBClick to Run (Security Update)

🔗 References (8)