Описание
Double free vulnerability in Microsoft Outlook 2007 SP3 and 2010 SP1 and SP2 allows remote attackers to execute arbitrary code by including many nested S/MIME certificates in an e-mail message, aka "Message Certificate Vulnerability."
Ссылки
- Vendor Advisory
- ExploitVendor Advisory
- US Government Resource
- Vendor Advisory
- ExploitVendor Advisory
- US Government Resource
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:microsoft:outlook:2007:sp3:*:*:*:*:*:*
cpe:2.3:a:microsoft:outlook:2010:sp1:*:*:*:*:x64:*
cpe:2.3:a:microsoft:outlook:2010:sp1:*:*:*:x86:*:*
cpe:2.3:a:microsoft:outlook:2010:sp2:*:*:*:*:x64:*
cpe:2.3:a:microsoft:outlook:2010:sp2:*:*:*:x86:*:*
EPSS
Процентиль: 97%
0.36716
Средний
9.3 Critical
CVSS2
Дефекты
CWE-399
Связанные уязвимости
github
больше 3 лет назад
Double free vulnerability in Microsoft Outlook 2007 SP3 and 2010 SP1 and SP2 allows remote attackers to execute arbitrary code by including many nested S/MIME certificates in an e-mail message, aka "Message Certificate Vulnerability."
EPSS
Процентиль: 97%
0.36716
Средний
9.3 Critical
CVSS2
Дефекты
CWE-399