Vulnerability Name: | CVE-2017-8572 (CCN-127652) | ||||||||||||
Assigned: | 2017-07-27 | ||||||||||||
Published: | 2017-07-27 | ||||||||||||
Updated: | 2021-08-30 | ||||||||||||
Summary: | Microsoft Outlook 2007 SP3, Outlook 2010 SP2, Outlook 2013 SP1, Outlook 2013 RT SP1, and Outlook 2016 as packaged in Microsoft Office allows an information disclosure vulnerability due to the way that it discloses the contents of its memory, aka "Microsoft Office Outlook Information Disclosure Vulnerability". | ||||||||||||
CVSS v3 Severity: | 5.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N) 4.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
4.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N)
| ||||||||||||
Vulnerability Type: | CWE-200 | ||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2017-8572 Source: BID Type: Third Party Advisory, VDB Entry 99453 Source: CCN Type: BID-99453 Microsoft Office Outlook CVE-2017-8572 Information Disclosure Vulnerability Source: SECTRACK Type: Third Party Advisory, VDB Entry 1039010 Source: XF Type: UNKNOWN ms-outlook-cve20178572-info-disc(127652) Source: CCN Type: Microsoft Security TechCenter Microsoft Office Outlook Information Disclosure Vulnerability Source: CONFIRM Type: Patch, Vendor Advisory https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8572 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
BACK |