CVE-2017-8545
published 2017-06-15CVE-2017-8545: A spoofing vulnerability exists in when Microsoft Outlook for Mac does not sanitize html properly, aka "Microsoft Outlook for Mac Spoofing Vulnerability".
PriorityP432medium6.5CVSS 3.0
AVNACLPRNUIRSUCNIHAN
EPSS
4.99%
91.3th percentile
A spoofing vulnerability exists in when Microsoft Outlook for Mac does not sanitize html properly, aka "Microsoft Outlook for Mac Spoofing Vulnerability".
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | outlook | — | — |
| microsoft_corporation | microsoft_outlook_for_mac | — | — |
| msrc | microsoft_outlook_2016_for_mac | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_msrc6.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-p237-h324-fx96: A spoofing vulnerability exists in when Microsoft Outlook for Mac does not sanitize html properly, aka "Microsoft Outlook for Mac Spoofing Vulnerabili
ghsa_unreviewed·2022-05-13
CVE-2017-8545 [MEDIUM] CWE-20 GHSA-p237-h324-fx96: A spoofing vulnerability exists in when Microsoft Outlook for Mac does not sanitize html properly, aka "Microsoft Outlook for Mac Spoofing Vulnerabili
A spoofing vulnerability exists in when Microsoft Outlook for Mac does not sanitize html properly, aka "Microsoft Outlook for Mac Spoofing Vulnerability".
Microsoft
Microsoft Outlook for Mac Spoofing Vulnerability
vendor_msrc·2017-06-13·CVSS 6.5
CVE-2017-8545 [MEDIUM] Microsoft Outlook for Mac Spoofing Vulnerability
Microsoft Outlook for Mac Spoofing Vulnerability
Description: A spoofing vulnerability exists in when Microsoft Outlook for Mac does not sanitize html or treat it in a safe manner. An attacker who successfully tricked the user could gain access to the user's authentication information or login credentials.
In an email attack scenario an attacker could exploit the vulnerability by sending an email with specific HTML tags, that could display a malicious authentication prompt.
The security update addresses the vulnerability by correcting how Outlook for Mac validates and sanitizes html input.
FAQ: Microsoft has released an update for Microsoft Office for Mac 2011 and Microsoft Office for Mac 2016 as a defense-in-depth measure.
Microsoft Office: Microsoft Office
Impact: Spoofing
Exploit S
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/98917http://www.securitytracker.com/id/1038664https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8545http://www.securityfocus.com/bid/98917http://www.securitytracker.com/id/1038664https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8545
2017-06-15
Published