CVE-2017-8663 is a remote code execution vulnerability affecting Microsoft Outlook 2007 SP3, 2010 SP2, 2013 SP1, 2013 RT SP1, and 2016. It stems from how Outlook parses specially crafted email messages, potentially leading to memory corruption. This vulnerability has a CVSS v3 score of 7.8 (High), indicating a local attack vector with low complexity, requiring user interaction, and potentially leading to high impact on confidentiality, integrity, and availability. While no public exploit code (Metasploit, Nuclei, ExploitDB) is available, and it's not listed on CISA's KEV catalog, it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2007CPE matchmatch criteria | cpe:2.3:a:microsoft:outlook:2007:sp3:*:*:*:*:*:* | ||
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:outlook:2010:sp2:*:*:*:*:*:* | ||
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:outlook:2013:sp1:*:*:*:*:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:outlook:2016:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.