A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in memory, aka "Microsoft Outlook Remote Code Execution Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Outlook.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Microsoft Office | — | Upgrade to the latest version of Microsoft Office | Aug 13, 2020 | Dec 12, 2018 |
| Msft | — | Security Update for Microsoft Outlook 2010 (KB4461576) 64-Bit EditionSecurity Update for Microsoft Outlook 2010 (KB4461576) 32-Bit EditionSecurity Update for Microsoft Outlook 2013 (KB4461556) 32-Bit EditionSecurity Update for Microsoft Outlook 2013 (KB4461556) 64-Bit Edition | Dec 11, 2018 | Dec 11, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub