logo

Outlook Home Page – Another Ruler Vector

ID: b5ff1221-6d9f-5124-a96c-c5a30c489a22

STIX ID: report--b5ff1221-6d9f-5124-a96c-c5a30c489a22

Feed Name: SensePost Blog

Threat Score
70/100

Date Published: 2017-10-11

Date Updated: 2026-04-29

...
...

SensePost describes a new Ruler vector that abuses Outlook's legacy Home Page feature to achieve remote code execution by embedding Outlook ActiveX controls in a hosted HTML page and using the ViewCtl/OutlookApplication handle to create a Wscript.Shell object; the technique was added to the Ruler tool (homepage support) and assigned CVE-2017-11774, with Microsoft releasing a patch to remove the feature and mitigate the attack. The post includes technical details for exploitation, how Ruler sets the PR_FOLDER_WEBVIEWINFO property via MAPI to deploy the homepage, recommendations for detection (NotRuler) and mitigation (apply KB4011162 and use strong account protections).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.