CVE-2017-11776 is an information disclosure vulnerability in Microsoft Outlook 2016 that allows an attacker to obtain the content of a user's emails. This high-severity vulnerability (CVSS 7.5) has a low attack complexity and does not require user interaction, leading to a complete compromise of confidentiality. While there is no public exploit code available or evidence of active exploitation, the vulnerability has garnered significant community discussion and media coverage, indicating awareness and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:outlook:2016:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.