Outlook Home Page – Another Ruler Vector
ID: b5ff1221-6d9f-5124-a96c-c5a30c489a22
STIX ID: report--b5ff1221-6d9f-5124-a96c-c5a30c489a22
Feed Name: SensePost Blog
SensePost describes a new Ruler vector that abuses Outlook's legacy Home Page feature to achieve remote code execution by embedding Outlook ActiveX controls in a hosted HTML page and using the ViewCtl/OutlookApplication handle to create a Wscript.Shell object; the technique was added to the Ruler tool (homepage support) and assigned CVE-2017-11774, with Microsoft releasing a patch to remove the feature and mitigate the attack. The post includes technical details for exploitation, how Ruler sets the PR_FOLDER_WEBVIEWINFO property via MAPI to deploy the homepage, recommendations for detection (NotRuler) and mitigation (apply KB4011162 and use strong account protections).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
