A Microsoft Outlook information disclosure issue affecting Outlook 2007 SP3, Outlook 2010 SP2, Outlook 2013 SP1, Outlook 2013 RT SP1, and Outlook 2016 as packaged in Microsoft Office. According to the provided content, crafted HTML email content could cause Outlook to disclose memory contents, and related research showed Outlook could also be abused to initiate outbound SMB or WebDAV requests when a victim opened or previewed a malicious email. NCC Group documented multiple HTML elements and URI schemes that could trigger remote resource access from the reading pane under default settings, including cases where external images were blocked. Microsoft partially addressed the issue in July 2017 under CVE-2017-8572, with additional payload coverage later associated with CVE-2017-11927 and a subsequent May 2018 update.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Microsoft Outlook issue that could be abused to trigger external SMB/WebDAV requests when an email was opened or viewed, potentially leaking SMB hashes or enabling email-view tracking. CVE-2017-8572 is described as a partial patch for this issue.
A Microsoft Outlook issue where crafted HTML emails could trigger external SMB/WebDAV requests when opened or previewed, enabling SMB hash leakage or email-view tracking; this CVE is described as a partial patch for the issue.
A Microsoft Outlook vulnerability related to SMB hash hijacking and user tracking via crafted HTML email content that could trigger external SMB/WebDAV requests when an email was opened or previewed.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.