Loading
Microsoft Outlook 2010 SP2, Outlook 2013 SP1 and RT SP1, and Outlook 2016 allow an attacker to execute arbitrary commands, due to how Microsoft Office handles objects in memory, aka "Microsoft Outlook Security Feature Bypass Vulnerability."
Use CWE-119, Microsoft vendor hub and Outlook product page to widen CVE-2017-11774 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-21361, CVE-2026-21260 and CVE-2025-29805 for nearby disclosures in the same product family. Additional editorial context is available in Weekly Security Roundup: Navigating the April 2026 Threat Landscape and Critical Framework Exploits.